Skip to content
Appaloosa Scout
Language selector
fr en

KEV · Actively exploited

CVE-2016-0189

CVE-2016-0189 is actively exploited (CISA KEV catalog) : high severity (CVSS 7.5), 0 tracked apps concerned, none still exposed on their current version.

Severity (CVSS)
7.5

NVD scale

Exploitation
Confirmed

CISA KEV · EPSS predicts 94.1 %

Tracked apps
0
Still exposed
0
Public exploit : ExploitDB

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 94.06% predictive model; CISA confirms active exploitation percentile 99.8%

CISA Known Exploited Vulnerability

Added to KEV
2022-03-28
Remediation deadline
2022-04-18
Required action
Apply updates per vendor instructions.
Ransomware
Unknown (not documented by CISA)
View on NVD ↗ CISA KEV catalog ↗ Advisory · docs.microsoft.com