LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Microsoft Internet Explorer Remote Code Execution 0-Day (CVE-2019-1367)

Microsoft released an out-of-band patch for a 0-day vulnerability in Internet Explorer yesterday. This memory corruption vulnerability in the Scripting Engine can lead to a Remote Code Execution (RCE) vulnerability, and, as implied by the fact that it’s a 0-day, is being exploited in-the-wild. The Scripting Engine typically represents the most affected software covered by Microsoft's monthly patch release so it's no surprise to find that this is a vulnerability discovered and exploited by bad actors.

The vulnerability would typically be exploited by convincing a victim using Internet Explorer to open a malicious URL. If your clients have automatic updates turned on, you shouldn't have to worry about patch deployment.

Technical details regarding the vulnerability are currently not publicly available, but we are able to confirm that Trustwave Secure Web Gateway (SWG) customers have been protected against attacks exploiting this CVE since Security Update 222 (released Jan 2019). Customers of Secure Email Gateway (SEG) using the Blended Threat Module (BTM) feature are similarly protected against malicious URLs exploiting this vulnerability sent via email.

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo