Vulnerability record · CVE-2018-8631 · published 12 December 2018
CVE-2018-8631: Internet Explorer memory corruption out-of-bounds write RCE
Microsoft · Internet Explorer
Internet Explorer 9, 10 and 11 improperly access objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. Because the affected browser was widely deployed and the flaw is memory-corruption class, a successful attack can run code in the context of the logged-on user.
Description
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (7.5) and very high EPSS with a public exploit, but exploitation requires user interaction and the affected browser is legacy.
What it is
Internet Explorer 9, 10 and 11 improperly access objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. Because the affected browser was widely deployed and the flaw is memory-corruption class, a successful attack can run code in the context of the logged-on user.
Impact
An attacker who convinces a user to open a crafted page can execute arbitrary code with the privileges of the current user, potentially leading to full system compromise if that user has administrative rights.
Attack surface
Reached over the network via a malicious or compromised web page rendered in Internet Explorer; no authentication is required, but user interaction (visiting the page) is needed per the CVSS vector UI:R.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.68493, 99.3rd percentile) and a public Exploit-DB entry (46001) exists, indicating exploit code is available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8631.
- Migrate users off Internet Explorer to a supported browser, or restrict IE use to sites that require it.
- Enforce Enhanced Protected Mode and 64-bit IE where IE must remain in use.
- Block or filter untrusted web content and restrict browsing to approved sites.
- Remove or disable the IE feature on systems that do not need it.
Detection
- Monitor for IE (iexplore.exe) crashes or abnormal child processes spawned from the browser.
- Hunt for exploit-related network requests to known malicious or newly registered domains from IE user agents.
- Review endpoint telemetry for memory-corruption indicators such as unexpected writes or code execution from browser processes.
- Check for the Exploit-DB 46001 sample or related indicators in web proxy and endpoint logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106118 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8631 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46001/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/106118 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8631 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46001/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8631 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8631), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.