Vulnerability record · CVE-2019-0768 · published 9 April 2019
CVE-2019-0768: Internet Explorer VBScript policy security feature bypass
Microsoft · Internet Explorer
Internet Explorer's VBScript execution policy fails to properly restrict VBScript under specific conditions, allowing requests that should be ignored. This is a security feature bypass that weakens a defense-in-depth control rather than granting direct code execution.
Description
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Automated analysis
medium priorityCVSS is only 4.3 and the flaw is a policy bypass requiring user interaction, but the high EPSS percentile and unpatched IE deployments keep it worth tracking.
What it is
Internet Explorer's VBScript execution policy fails to properly restrict VBScript under specific conditions, allowing requests that should be ignored. This is a security feature bypass that weakens a defense-in-depth control rather than granting direct code execution.
Impact
An attacker can bypass the VBScript execution policy, potentially enabling script content that the policy was meant to block. The CVSS vector shows only low confidentiality impact, so the direct gain is limited.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically a victim visiting a crafted page or opening crafted content in Internet Explorer.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is high at 0.485 (98.8th percentile), indicating elevated predicted exploitation activity despite the absence of confirmed in-the-wild use.
What to do
- Apply the Microsoft security update referenced in the vendor advisory.
- Disable or restrict VBScript execution in Internet Explorer via policy where business needs allow.
- Migrate users off Internet Explorer to a supported browser.
- Block or warn on untrusted web content and enforce Protected Mode/Enhanced Security Configuration.
- Monitor for unexpected VBScript execution in browser processes.
Detection
- Alert on Internet Explorer processes (iexplore.exe) spawning script hosts or executing VBScript unexpectedly.
- Review proxy and web logs for access to pages delivering VBScript content to IE clients.
- Audit endpoint policy settings for VBScript execution restrictions and flag deviations.
- Correlate IE crash or script-error telemetry with suspicious browsing activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0768 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0768 | PatchVendor Advisory |
Track CVE-2019-0768 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.