← Vulnerability feed

Vulnerability record · CVE-2016-0189 · published 11 May 2016

CVE-2016-0189: Microsoft JScript and VBScript engines memory corruption in Internet Explorer

Microsoft · Jscript

The JScript 5.8 and VBScript 5.7/5.8 engines used by Internet Explorer 9 through 11 contain an out-of-bounds write that corrupts memory when a crafted web page is processed. A remote attacker can trigger it through browsing, leading to arbitrary code execution or a denial of service. It is a distinct issue from CVE-2016-0187 and was patched in May 2016.

7.5 CVSS 3.1 High CISA KEV since 28 Mar 2022 Known ransomware use EPSS 94% · top 0.2% CWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score, v2 7.6
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and public exploit code exists, so unpatched IE systems face active exploitation risk.

What it is

The JScript 5.8 and VBScript 5.7/5.8 engines used by Internet Explorer 9 through 11 contain an out-of-bounds write that corrupts memory when a crafted web page is processed. A remote attacker can trigger it through browsing, leading to arbitrary code execution or a denial of service. It is a distinct issue from CVE-2016-0187 and was patched in May 2016.

Impact

Successful exploitation lets an attacker execute arbitrary code in the context of the affected scripting engine, or crash the browser. In practice this yields code execution on the victim's machine under the user's privileges.

Attack surface

Reached over the network by a victim visiting a crafted web site or opening attacker-supplied content that invokes the vulnerable scripting engine. No authentication is required, but user interaction (browsing to or opening the page) is needed per the CVSS vector.

Exploitation

Listed in CISA KEV since 2022-03-28 with known ransomware campaign use, and EPSS is very high (0.94, 99.8th percentile). Public exploit code exists (Exploit-DB 40118) and a detailed write-up describes its use.

What to do

  • Apply the Microsoft updates referenced in MS16-051 and MS16-053, or later cumulative updates, to affected Windows and IE installations.
  • Retire or upgrade Internet Explorer 9 through 11 where possible; migrate users to a supported browser.
  • Restrict or block execution of legacy JScript/VBScript content and untrusted ActiveX/scripting in IE via policy.
  • Enforce network controls and email/web filtering to block known exploit hosts and malicious attachments.
  • Monitor for and isolate systems that cannot be patched, given confirmed ransomware use.

Detection

  • Hunt for IE processes (iexplore.exe) spawning child processes such as cmd.exe, powershell.exe, wscript.exe or rundll32.exe.
  • Alert on script engine crashes or memory-corruption events in jscript.dll/vbscript.dll from IE.
  • Review proxy and DNS logs for connections to known exploit-kit or malicious domains tied to this CVE.
  • Correlate endpoint telemetry for exploit artifacts and post-exploitation behavior on hosts still running IE 9-11.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-0189 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Internet Explorer Memory Corruption Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0189 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2017-0222Internet Explorer memory corruption out-of-bounds write RCEInternet Explorer improperly accesses objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. The …KEVEPSS 30%analysed8.8CVE-2017-0210Internet Explorer cross-domain policy bypass elevation of privilegeInternet Explorer fails to properly enforce cross-domain policies, allowing an attacker to read information from one domain and inject it into anothe…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2016-0189), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.