LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

CVE-2019-1429: (Another) Microsoft Internet Explorer 0-Day

November’s Patch Tuesday from Microsoft included a patch for yet another Internet Explorer 0-day, not too long after the out-of-band patch we talked about in September. Once more this is a memory corruption vulnerability in the Scripting Engine, which can lead to a Remote Code Execution (RCE) vulnerability. According to Microsoft, this vulnerability is known to be exploited in-the-wild.

Also similar to the last 0-day, we are able to confirm that Trustwave Secure Web Gateway (SWG) customers have been protected against attacks exploiting this CVE since Security Update 222 (released Jan 2019). Customers of Secure Email Gateway (SEG) using the Blended Threat Module (BTM) feature are similarly protected against malicious URLs exploiting this vulnerability sent via email.

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo