Vulnerability record · CVE-2018-0935 · published 14 March 2018
CVE-2018-0935: Internet Explorer Scripting Engine Memory Corruption RCE
Microsoft · Internet Explorer
Internet Explorer's scripting engine mishandles objects in memory, producing a use-after-free and out-of-bounds write. A remote attacker can corrupt memory and execute code in the context of the browser. The flaw affects IE across a wide range of Windows client and server releases.
Description
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0889, CVE-2018-0893, and CVE-2018-0925.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a public exploit and very high EPSS, but exploitation requires user interaction and the product is legacy.
What it is
Internet Explorer's scripting engine mishandles objects in memory, producing a use-after-free and out-of-bounds write. A remote attacker can corrupt memory and execute code in the context of the browser. The flaw affects IE across a wide range of Windows client and server releases.
Impact
Successful exploitation gives the attacker remote code execution with the privileges of the current user. On a system where the user has administrative rights, the attacker could take full control of the host.
Attack surface
Reached over the network via a crafted web page or content rendered by Internet Explorer; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must be lured into viewing the malicious content.
Exploitation
A public exploit exists (Exploit-DB 44404) and EPSS is high at 0.556 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-0935.
- Retire or stop using Internet Explorer; migrate browsing to a supported modern browser.
- Disable or restrict IE use on Windows Server and legacy Windows systems where it is not required.
- Enforce network controls and email/web filtering to block known exploit pages and malicious attachments.
- Run users with least privilege so code execution does not immediately yield administrative rights.
Detection
- Monitor for IE (iexplore.exe) crashes and abnormal child process creation, especially Office or script interpreters spawned by the browser.
- Hunt for known exploit artifacts and shellcode patterns tied to Exploit-DB 44404 in web proxy and endpoint logs.
- Alert on IE rendering of untrusted or newly registered domains and on exploit-kit redirect chains.
- Review endpoint telemetry for memory corruption indicators and suspicious post-exploitation behavior from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103298 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040510 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0935 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44404/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/103298 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040510 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0935 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44404/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-0935 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.