HTTP: Microsoft Internet Explorer CVE-2018-0935 Scripting Engine Memory Corruption

This signature detects an attempt to exploit an Use-After-Free Vulnerability in Microsoft Internet Explorer Scripting Engine. Successful exploitation could allow an attacker to execute arbitrary code into the application's context.

Extended Description

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0889, CVE-2018-0893, and CVE-2018-0925.

References

BugTraq: 103298

CVE: CVE-2018-0935

Short Name
HTTP:STC:IE:CVE-2018-0935-MC
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-0935 Corruption Engine Explorer Internet Memory Microsoft Scripting bid:103298
Release Date
03/13/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
CVSS Score

7.6

Found a potential security threat?