CVE detail
CVE-2016-0189
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
48 source links · newest first
The 5th installment in a series of posts tracking web-based threats over time from our Email Link Analysis (ELINK) system., specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
vendorunit42.paloaltonetworks.comNov 1, 2019, 1:00 PM- Exploit kits: summer 2019 reviewMalwarebytes Labs
In the months since our last spring review, there has been some interesting activity from several exploit kits. While the playing…
newswww.malwarebytes.comJul 29, 2019, 5:00 PM Our latest research evaluates the data from our Email Link Analysis (ELINK) system and shows France rises to number one for malicious URL hosting, the US to number one for phishing for Web-based threats in the last quarter of 2018. Learn more details in the full report.
vendorunit42.paloaltonetworks.comMay 30, 2019, 4:00 PMEight of the top ten most exploited vulnerabilities in 2018 affected Microsoft products. Only one — but the second most exploited — was an Adobe vulnerability. The last one, ranking at the ninth most exploited vulnerability of 2018, was an Android vulnerability.
newswww.securityweek.comMar 19, 2019, 4:26 PMOur Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PM- Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7Unit42
Email Link Analysis from Unit 42 reveals that the United States remain the number one hoster of malicious web addresses for Q2 2018.
vendorunit42.paloaltonetworks.comSep 5, 2018, 3:12 AM New Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. Malware researchers from Trend Micro have spotted a new exploit kit, tracked as Underminer exploit kit, delivering a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. “We […]
newssecurityaffairs.comJul 29, 2018, 8:54 AM- ‘Hidden Bee’ miner delivered via improved drive-by download toolkitMalwarebytes Labs
This blog post was authored by @hasherezade and Jérôme Segura.We recently detected a drive-by download attack trying to exploit CVE-2018-4878, a vulnerability in Flash…
newswww.malwarebytes.comJul 25, 2018, 5:00 PM Unit 42 investigates the latest trends in web-based threats.
vendorunit42.paloaltonetworks.comJun 20, 2018, 2:00 AMCyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities. “Since both Flash and the VBScript engine are […]
newssecurityaffairs.comJun 14, 2018, 7:06 AMExploit kits (EKs) might not be as dominant as they were several years ago, but they continue to exist and most of them already adopted exploits for recently discovered Flash and Internet Explorer zero-day vulnerabilities.
newswww.securityweek.comJun 13, 2018, 3:50 PM- Exploit kits: Spring 2018 reviewMalwarebytes Labs
Since our last report on exploit kits, there have been some new developments with the wider adoption of the February Flash…
newswww.malwarebytes.comJun 11, 2018, 5:00 PM Cyber criminals recently added the code for the CVE-2018-8174 Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. Crooks recently added the code for an Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. The Internet Explorer zero-day vulnerability, tracked as CVE-2018-8174, was first discovered a few weeks ago, it affects VBScript implemented in Internet Explorer and Microsoft […]
newssecurityaffairs.comJun 3, 2018, 7:32 AM- Internet Explorer zero-day: browser is once again under attackMalwarebytes Labs
Update (2018-06-04): CVE-2018-8174 has been added to the Magnitude exploit kit (Source: MDNC).Update (2018-05-25): CVE-2018-8174 has been added to the RIG exploit…
newswww.malwarebytes.comMay 9, 2018, 5:00 PM - Magnitude exploit kit switches to GandCrab ransomwareMalwarebytes Labs
The GandCrab ransomware is reaching far and wide via malspam, social engineering schemes, and exploit kit campaigns. On April 16, we…
newswww.malwarebytes.comApr 16, 2018, 5:00 PM - Exploit kits: Winter 2018 reviewMalwarebytes Labs
In the past, we used to do a blog series on exploit kits where we would periodically check in on the…
newswww.malwarebytes.comMar 28, 2018, 5:00 PM Cybercriminals are shifting their focus from Adobe to Microsoft consumer products, and are now concentrating more on targeted attacks than on web-based exploit kits.
newswww.securityweek.comMar 27, 2018, 3:13 PMDuring our web crawls we sometimes come across bizarre findings or patterns we haven’t seen before. This was the case with…
newswww.malwarebytes.comFeb 21, 2018, 5:00 PM- Matrix Ransomware being distributed through malvertisingSecurity Affairs
Security expert Jérôme Segura from Malwarebytes has spotted that Matrix Ransomware has risen again, it is now being distributed through malvertising. Malware researcher Jérôme Segura from Malwarebytes has discovered that Matrix Ransomware is now being distributed through malvertising campaign. https://twitter.com/EKFiddle/status/923660551095427072 The Matrix Ransomware was first spotted in 2016, in April 2017 the threat intelligence expert Brad Duncan uncovered the EITest campaign using […]
newssecurityaffairs.comOct 29, 2017, 1:47 PM - New Magniber Ransomware EmergesSecurityWeek
A brand new ransomware family currently being distributed through the Magnitude exploit kit appears to be targeting South Korean users exclusively, security researchers have discovered.
newswww.securityweek.comOct 19, 2017, 5:09 PM Unit 42 uncovers FreeMilk: a highly targeted spear phishing campaign using hijacked conversations to deliver malware.
vendorunit42.paloaltonetworks.comOct 5, 2017, 12:00 PM- RIG exploit kit distributes Princess ransomwareMalwarebytes Labs
We have identified a new drive-by download campaign that distributes the Princess ransomware (AKA PrincessLocker), leveraging compromised websites and the RIG…
newswww.malwarebytes.comAug 30, 2017, 5:00 PM According to a new report published by FireEye, crooks have been using the Neptune exploit kit to deliver cryptocurrency miners via malvertising campaigns. According to experts at FireEye, crooks are exploiting the Neptune exploit kit (aka Terror EK, Eris, and Blaze) to delivery cryptocurrency miners via malvertising campaigns. The Neptune exploit kit was first spotted in January and was […]
newssecurityaffairs.comAug 23, 2017, 8:10 AMA new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.
newswww.securityweek.comAug 15, 2017, 12:46 PM- The Disdain exploit kit appears in the threat landscapeSecurity Affairs
The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]
newssecurityaffairs.comAug 15, 2017, 7:48 AM - Exploit kits: Winter 2017 reviewMalwarebytes Labs
A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…
newswww.malwarebytes.comMar 8, 2017, 5:00 PM It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.
newswww.securityweek.comJan 20, 2017, 4:16 PMBased on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]
newswww.csoonline.comJan 17, 2017, 7:00 PM- New Terror Exploit Kit EmergesSecurityWeek
After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.
newswww.securityweek.comJan 10, 2017, 4:59 PM The operators behind the Sundown exploit kit have started using two Microsoft Edge flaws just a few days after researchers published a PoC exploit. The Sundown exploit kit is becoming one of the most popular crimeware kits in the hacking underground. The last time we saw it was at the end of 2016 when malware researchers spotted a […]
newssecurityaffairs.comJan 10, 2017, 9:30 AM- Edge Exploits Added to Sundown EKSecurityWeek
The maintainers of the Sundown exploit kit have started using two Microsoft Edge vulnerabilities just a few days after researchers published a proof-of-concept (PoC) exploit.
newswww.securityweek.comJan 9, 2017, 2:56 PM - Sundown Exploit Kit now leverages on the steganographySecurity Affairs
A new variant of the Sundown exploit kit leverages on steganography to hide exploit code in harmless-looking image files. Security experts from Trend Micro have spotted a new version of the Sundown exploit kit that exploits steganography in order to hide malicious code in harmless-looking image files. The use of steganography was recently observed in the malvertising campaigns conducted […]
newssecurityaffairs.comDec 30, 2016, 7:46 PM - Sundown Exploit Kit Starts Using SteganographySecurityWeek
A new version of the Sundown exploit kit uses a technique called steganography to hide its exploits in harmless-looking image files, Trend Micro reported on Thursday.
newswww.securityweek.comDec 30, 2016, 10:31 AM - Adobe Flash Player flaws remain the most used by Exploit KitsSecurity Affairs
Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]
newssecurityaffairs.comDec 6, 2016, 8:18 PM The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.
newswww.securityweek.comDec 6, 2016, 3:28 PM- Chinese hackers behind the CNACOM campaign hit Taiwan websiteSecurity Affairs
Security firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM’ that was targeting government organization in Taiwan. Security researchers from the firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM‘ that was targeting government organization in Taiwan. According to the researchers, the hackers behind the CNACOM campaign are linked to China […]
newssecurityaffairs.comDec 6, 2016, 7:07 AM - China-Linked Spies Target Taiwan With IE ExploitSecurityWeek
A cyberespionage group linked to China has been spotted targeting government organizations in Taiwan using an Internet Explorer vulnerability patched by Microsoft earlier this year.
newswww.securityweek.comDec 5, 2016, 12:34 PM - Exploit kits: Fall 2016 reviewMalwarebytes Labs
There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…
newswww.malwarebytes.comNov 8, 2016, 5:00 PM - Yet another Sundown EK variant? (updated)Malwarebytes Labs
Update (11/6/2016): TrendLabs recently published (11/04/2016) their own research on this new Sundown EK, which turns out to be a new exploit kit…
newswww.malwarebytes.comOct 17, 2016, 5:00 PM - Sundown Exploit Kit Outsources Coding WorkSecurityWeek
Sundown, a relatively new exploit kit (EK), is outsourcing panel and Domain Generation Algorithm (DGA) coding work and stealing exploits in an attempt to improve its presence on the EK scene.
newswww.securityweek.comSep 5, 2016, 1:46 PM The developers of the RIG exploit kit appear to be testing new infection methods and a different type of URL pattern for command and control (C&C) communications that could help the threat evade detection.
newswww.securityweek.comSep 1, 2016, 10:26 AM- Malvertising campaign delivers two exploit kits, same payloadMalwarebytes Labs
Malvertising remains a favourite distribution platform for pushing out malware and we typically see certain exploit kits associated with particular campaigns. As…
newswww.malwarebytes.comAug 9, 2016, 5:00 PM Operators behind the Neutrino EK have added the code to exploit an Internet Explorer flaw that was recently patched with the release of the MS16-053. Operators behind the infamous Neutrino EK have recently added the code to exploit an Internet Explorer vulnerability that was patched with the release of the MS16-053 security bulletin. The MS16-053 bulletin patched […]
newssecurityaffairs.comJul 15, 2016, 1:20 PMThe developers of the Neutrino exploit kit have added a recently patched Internet Explorer vulnerability to their arsenal after researchers published a proof-of-concept (PoC) exploit.
newswww.securityweek.comJul 15, 2016, 7:44 AMAdobe has updated Flash Player for Windows, Mac and Linux to address a total of 25 vulnerabilities, including a zero-day that has been exploited in the wild. Flash Player 21.0.0.242 and 11.2.202.616 patch type confusion, use-aftre-free, buffer overflow, directory search path, and various memory corruption vulnerabilities that can lead to arbitrary code execution.
newswww.securityweek.comMay 12, 2016, 4:26 PMHello, zero-days. And yes, you should be busy patching them, but Adobe isn’t releasing one of the zero-day fixes for Flash Player until tomorrow (May 12)—even though it is currently being used in real-world attacks. Microsoft released 16 security bulletins, eight of which are rated critical for remote code execution (RCE) and includes a fix […]
newswww.csoonline.comMay 11, 2016, 5:20 PMMicrosoft released patches for 51 vulnerabilities Tuesday, including one affecting Internet Explorer that hackers have exploited in targeted attacks against organizations in South Korea. The Microsoft patches were covered in 16 security bulletins, eight rated critical and eight important. The affected products include Windows, Internet Explorer, Microsoft Edge, Office and Microsoft .NET Framework. The patches […]
newswww.csoonline.comMay 11, 2016, 11:54 AMMicrosoft released on Tuesday 16 security bulletins to patch more than 30 vulnerabilities, including JScript and VBScript zero-days exploited in attacks targeting users in South Korea.
newswww.securityweek.comMay 11, 2016, 9:08 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-0149CVSS 8.8 · High
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Ex…
- CVE-2017-0222CVSS 8.8 · High
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is…
- CVE-2015-2502CVSS 8.8 · High
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Cor…
- CVE-2017-0059CVSS 4.3 · Medium
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disc…
KEV listed - CVE-2016-3298CVSS 6.5 · Medium
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to deter…
KEV listed13 mentions - CVE-2016-3351CVSS 6.5 · Medium
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Discl…
KEV listed12 mentions