Skip to main content

CVE detail

CVE-2016-0189

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

CVSS 7.5 · HighBuzz score 69.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
48 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
48 source links · newest first
  • The 5th installment in a series of posts tracking web-based threats over time from our Email Link Analysis (ELINK) system., specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.

    vendorunit42.paloaltonetworks.comNov 1, 2019, 1:00 PM
  • Exploit kits: summer 2019 reviewMalwarebytes Labs

    In the months since our last spring review, there has been some interesting activity from several exploit kits. While the playing…

    newswww.malwarebytes.comJul 29, 2019, 5:00 PM
  • Our latest research evaluates the data from our Email Link Analysis (ELINK) system and shows France rises to number one for malicious URL hosting, the US to number one for phishing for Web-based threats in the last quarter of 2018. Learn more details in the full report.

    vendorunit42.paloaltonetworks.comMay 30, 2019, 4:00 PM
  • Eight of the top ten most exploited vulnerabilities in 2018 affected Microsoft products. Only one — but the second most exploited — was an Adobe vulnerability. The last one, ranking at the ninth most exploited vulnerability of 2018, was an Android vulnerability.

    newswww.securityweek.comMar 19, 2019, 4:26 PM
  • Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.

    vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PM
  • Email Link Analysis from Unit 42 reveals that the United States remain the number one hoster of malicious web addresses for Q2 2018.

    vendorunit42.paloaltonetworks.comSep 5, 2018, 3:12 AM
  • New Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. Malware researchers from Trend Micro have spotted a new exploit kit, tracked as Underminer exploit kit, delivering a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. “We […]

    newssecurityaffairs.comJul 29, 2018, 8:54 AM
  • This blog post was authored by @hasherezade and Jérôme Segura.We recently detected a drive-by download attack trying to exploit CVE-2018-4878, a vulnerability in Flash…

    newswww.malwarebytes.comJul 25, 2018, 5:00 PM
  • Unit 42 investigates the latest trends in web-based threats.

    vendorunit42.paloaltonetworks.comJun 20, 2018, 2:00 AM
  • Cyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities. “Since both Flash and the VBScript engine are […]

    newssecurityaffairs.comJun 14, 2018, 7:06 AM
  • Exploit kits (EKs) might not be as dominant as they were several years ago, but they continue to exist and most of them already adopted exploits for recently discovered Flash and Internet Explorer zero-day vulnerabilities.

    newswww.securityweek.comJun 13, 2018, 3:50 PM
  • Exploit kits: Spring 2018 reviewMalwarebytes Labs

    Since our last report on exploit kits, there have been some new developments with the wider adoption of the February Flash…

    newswww.malwarebytes.comJun 11, 2018, 5:00 PM
  • Cyber criminals recently added the code for the CVE-2018-8174 Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. Crooks recently added the code for an Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. The Internet Explorer zero-day vulnerability, tracked as CVE-2018-8174, was first discovered a few weeks ago, it affects VBScript implemented in Internet Explorer and Microsoft […]

    newssecurityaffairs.comJun 3, 2018, 7:32 AM
  • Update (2018-06-04): CVE-2018-8174 has been added to the Magnitude exploit kit (Source: MDNC).Update (2018-05-25): CVE-2018-8174 has been added to the RIG exploit…

    newswww.malwarebytes.comMay 9, 2018, 5:00 PM
  • The GandCrab ransomware is reaching far and wide via malspam, social engineering schemes, and exploit kit campaigns. On April 16, we…

    newswww.malwarebytes.comApr 16, 2018, 5:00 PM
  • Exploit kits: Winter 2018 reviewMalwarebytes Labs

    In the past, we used to do a blog series on exploit kits where we would periodically check in on the…

    newswww.malwarebytes.comMar 28, 2018, 5:00 PM
  • Cybercriminals are shifting their focus from Adobe to Microsoft consumer products, and are now concentrating more on targeted attacks than on web-based exploit kits.

    newswww.securityweek.comMar 27, 2018, 3:13 PM
  • During our web crawls we sometimes come across bizarre findings or patterns we haven’t seen before. This was the case with…

    newswww.malwarebytes.comFeb 21, 2018, 5:00 PM
  • Security expert Jérôme Segura from Malwarebytes has spotted that Matrix Ransomware has risen again, it is now being distributed through malvertising. Malware researcher Jérôme Segura from Malwarebytes has discovered that Matrix Ransomware is now being distributed through malvertising campaign. https://twitter.com/EKFiddle/status/923660551095427072 The Matrix Ransomware was first spotted in 2016, in April 2017 the threat intelligence expert Brad Duncan uncovered the EITest campaign using […]

    newssecurityaffairs.comOct 29, 2017, 1:47 PM
  • New Magniber Ransomware EmergesSecurityWeek

    A brand new ransomware family currently being distributed through the Magnitude exploit kit appears to be targeting South Korean users exclusively, security researchers have discovered.

    newswww.securityweek.comOct 19, 2017, 5:09 PM
  • Unit 42 uncovers FreeMilk: a highly targeted spear phishing campaign using hijacked conversations to deliver malware.

    vendorunit42.paloaltonetworks.comOct 5, 2017, 12:00 PM
  • RIG exploit kit distributes Princess ransomwareMalwarebytes Labs

    We have identified a new drive-by download campaign that distributes the Princess ransomware (AKA PrincessLocker), leveraging compromised websites and the RIG…

    newswww.malwarebytes.comAug 30, 2017, 5:00 PM
  • According to a new report published by FireEye, crooks have been using the Neptune exploit kit to deliver cryptocurrency miners via malvertising campaigns. According to experts at FireEye, crooks are exploiting the Neptune exploit kit (aka Terror EK, Eris, and Blaze) to delivery cryptocurrency miners via malvertising campaigns. The Neptune exploit kit was first spotted in January and was […]

    newssecurityaffairs.comAug 23, 2017, 8:10 AM
  • A new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.

    newswww.securityweek.comAug 15, 2017, 12:46 PM
  • The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]

    newssecurityaffairs.comAug 15, 2017, 7:48 AM
  • Exploit kits: Winter 2017 reviewMalwarebytes Labs

    A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…

    newswww.malwarebytes.comMar 8, 2017, 5:00 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Based on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]

    newswww.csoonline.comJan 17, 2017, 7:00 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • The operators behind the Sundown exploit kit have started using two Microsoft Edge flaws just a few days after researchers published a PoC exploit. The Sundown exploit kit is becoming one of the most popular crimeware kits in the hacking underground. The last time we saw it was at the end of 2016 when malware researchers spotted a […]

    newssecurityaffairs.comJan 10, 2017, 9:30 AM
  • Edge Exploits Added to Sundown EKSecurityWeek

    The maintainers of the Sundown exploit kit have started using two Microsoft Edge vulnerabilities just a few days after researchers published a proof-of-concept (PoC) exploit.

    newswww.securityweek.comJan 9, 2017, 2:56 PM
  • A new variant of the Sundown exploit kit leverages on steganography to hide exploit code in harmless-looking image files. Security experts from Trend Micro have spotted a new version of the Sundown exploit kit that exploits steganography in order to hide malicious code in harmless-looking image files. The use of steganography was recently observed in the malvertising campaigns conducted […]

    newssecurityaffairs.comDec 30, 2016, 7:46 PM
  • A new version of the Sundown exploit kit uses a technique called steganography to hide its exploits in harmless-looking image files, Trend Micro reported on Thursday.

    newswww.securityweek.comDec 30, 2016, 10:31 AM
  • Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]

    newssecurityaffairs.comDec 6, 2016, 8:18 PM
  • The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.

    newswww.securityweek.comDec 6, 2016, 3:28 PM
  • Security firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM’ that was targeting government organization in Taiwan. Security researchers from the firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM‘ that was targeting government organization in Taiwan. According to the researchers, the hackers behind the CNACOM campaign are linked to China […]

    newssecurityaffairs.comDec 6, 2016, 7:07 AM
  • A cyberespionage group linked to China has been spotted targeting government organizations in Taiwan using an Internet Explorer vulnerability patched by Microsoft earlier this year.

    newswww.securityweek.comDec 5, 2016, 12:34 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • Yet another Sundown EK variant? (updated)Malwarebytes Labs

    Update (11/6/2016): TrendLabs recently published (11/04/2016) their own research on this new Sundown EK, which turns out to be a new exploit kit…

    newswww.malwarebytes.comOct 17, 2016, 5:00 PM
  • Sundown, a relatively new exploit kit (EK), is outsourcing panel and Domain Generation Algorithm (DGA) coding work and stealing exploits in an attempt to improve its presence on the EK scene.

    newswww.securityweek.comSep 5, 2016, 1:46 PM
  • The developers of the RIG exploit kit appear to be testing new infection methods and a different type of URL pattern for command and control (C&C) communications that could help the threat evade detection.

    newswww.securityweek.comSep 1, 2016, 10:26 AM
  • Malvertising remains a favourite distribution platform for pushing out malware and we typically see certain exploit kits associated with particular campaigns. As…

    newswww.malwarebytes.comAug 9, 2016, 5:00 PM
  • Operators behind the Neutrino EK have added the code to exploit an Internet Explorer flaw that was recently patched with the release of the MS16-053. Operators behind the infamous Neutrino EK have recently added the code to exploit an Internet Explorer vulnerability that was patched with the release of the MS16-053 security bulletin. The MS16-053 bulletin patched […]

    newssecurityaffairs.comJul 15, 2016, 1:20 PM
  • The developers of the Neutrino exploit kit have added a recently patched Internet Explorer vulnerability to their arsenal after researchers published a proof-of-concept (PoC) exploit.

    newswww.securityweek.comJul 15, 2016, 7:44 AM
  • Adobe has updated Flash Player for Windows, Mac and Linux to address a total of 25 vulnerabilities, including a zero-day that has been exploited in the wild. Flash Player 21.0.0.242 and 11.2.202.616 patch type confusion, use-aftre-free, buffer overflow, directory search path, and various memory corruption vulnerabilities that can lead to arbitrary code execution.

    newswww.securityweek.comMay 12, 2016, 4:26 PM
  • Hello, zero-days. And yes, you should be busy patching them, but Adobe isn’t releasing one of the zero-day fixes for Flash Player until tomorrow (May 12)—even though it is currently being used in real-world attacks. Microsoft released 16 security bulletins, eight of which are rated critical for remote code execution (RCE) and includes a fix […]

    newswww.csoonline.comMay 11, 2016, 5:20 PM
  • Microsoft released patches for 51 vulnerabilities Tuesday, including one affecting Internet Explorer that hackers have exploited in targeted attacks against organizations in South Korea. The Microsoft patches were covered in 16 security bulletins, eight rated critical and eight important. The affected products include Windows, Internet Explorer, Microsoft Edge, Office and Microsoft .NET Framework. The patches […]

    newswww.csoonline.comMay 11, 2016, 11:54 AM
  • Microsoft released on Tuesday 16 security bulletins to patch more than 30 vulnerabilities, including JScript and VBScript zero-days exploited in attacks targeting users in South Korea.

    newswww.securityweek.comMay 11, 2016, 9:08 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence