CVE-2019-0676
Microsoft Internet Explorer 10 … 11
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NSummary
CVE-2019-0676 is a medium-severity an unspecified weakness vulnerability in Microsoft Windows 10 1709. Its CVSS base score is 6.5 (Medium).
Operationally, ranked in the top 6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
An information disclosure vulnerability exists in Internet Explorer when the browser improperly handles objects in memory. The flaw, tracked as CVE-2019-0676, allows an attacker to determine whether specific files are present on a victim's disk. It carries a CVSS 3.1 score of 6.5 reflecting network attack vector, low attack complexity, no required privileges, and required user interaction.
An unauthenticated remote attacker can exploit the issue by convincing a user to visit a malicious web page or open a specially crafted document in Internet Explorer. Successful exploitation discloses the presence or absence of arbitrary files on disk without granting code execution or further system access.
Microsoft published an advisory addressing the vulnerability, and the issue appears in CISA's catalog of known exploited vulnerabilities, indicating confirmed in-the-wild use. No additional mitigation details beyond the vendor advisory are provided in the source references.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2019-1436
Vulnerability Data
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
- CWE(s)
- KEV Date Added
- 23 May 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.