Vulnerability record · CVE-2019-0676 · published 5 March 2019
CVE-2019-0676: Internet Explorer memory handling information disclosure
Microsoft · Internet Explorer
Internet Explorer mishandles objects in memory, allowing an attacker to probe for the presence of files on the victim's disk. The flaw is an information disclosure issue, not code execution, but it leaks local file existence that can support later targeted attacks. Microsoft rates it medium severity with a network vector and required user interaction.
Description
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is in CISA's KEV catalog with confirmed in-the-wild exploitation, but the direct impact is limited to file existence disclosure rather than code execution.
What it is
Internet Explorer mishandles objects in memory, allowing an attacker to probe for the presence of files on the victim's disk. The flaw is an information disclosure issue, not code execution, but it leaks local file existence that can support later targeted attacks. Microsoft rates it medium severity with a network vector and required user interaction.
Impact
An attacker can determine whether specific files exist on the target's disk, which aids reconnaissance and follow-on exploitation. No data modification or code execution is gained directly from this flaw.
Attack surface
Reached over the network via a crafted web page or content rendered in Internet Explorer; the CVSS vector shows no privileges required but user interaction is required. The victim must open or view attacker-controlled content in the browser.
Exploitation
CVE-2019-0676 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, though no ransomware use is documented. EPSS gives a 30-day probability of about 7.5 percent (94th percentile), and references include a vendor patch advisory.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2019-0676.
- Retire or disable Internet Explorer where possible and move users to a supported browser.
- Enforce attachment and web content filtering to reduce exposure to crafted pages.
- Restrict browsing to trusted sites and block untrusted ActiveX or script content in IE.
- Track CISA KEV remediation deadlines and confirm patching across all endpoints.
Detection
- Monitor for Internet Explorer crashes or unusual memory-related error events on endpoints.
- Review proxy and web logs for IE user agents accessing suspicious or newly registered domains.
- Hunt for processes reading file metadata or probing file paths from within IE or its child processes.
- Correlate IE usage with subsequent reconnaissance or file access activity on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0676 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Microsoft Internet Explorer Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106886 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0676 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/106886 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0676 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0676 | US Government Resource |
Track CVE-2019-0676 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0676), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.