First published: Tue Mar 05 2019(Updated: )
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | ||
All of | ||
Internet Explorer | =10 | |
Microsoft Windows Server 2012 x64 | ||
All of | ||
Internet Explorer | =11 | |
Any of | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server 2008 Itanium | =r2 | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Internet Explorer | =10 | |
Microsoft Windows Server 2012 x64 | ||
Internet Explorer | =11 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server 2008 Itanium | =r2 | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0676 is rated as important, indicating it could allow information disclosure when exploited.
CVE-2019-0676 allows an attacker to test for the presence of files on the victim's disk.
To fix CVE-2019-0676, users should apply the latest security updates or patches provided by Microsoft.
CVE-2019-0676 affects versions 10 and 11 of Internet Explorer.
Currently, no specific workarounds have been provided for CVE-2019-0676, thus updating is the best course of action.