Cyber Resilience

CVE-2019-0676

Microsoft Internet Explorer 10 … 11

CISA KEVActive ExploitationEUVD Exploited
Published
05 March 2019
Modified
29 October 2025
KEV Added
23 May 2022
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score 0.075 94th percentile
Risk Priority 76 floored blend · peak EPSS

Summary

CVE-2019-0676 is a medium-severity an unspecified weakness vulnerability in Microsoft Windows 10 1709. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

An information disclosure vulnerability exists in Internet Explorer when the browser improperly handles objects in memory. The flaw, tracked as CVE-2019-0676, allows an attacker to determine whether specific files are present on a victim's disk. It carries a CVSS 3.1 score of 6.5 reflecting network attack vector, low attack complexity, no required privileges, and required user interaction.

An unauthenticated remote attacker can exploit the issue by convincing a user to visit a malicious web page or open a specially crafted document in Internet Explorer. Successful exploitation discloses the presence or absence of arbitrary files on disk without granting code execution or further system access.

Microsoft published an advisory addressing the vulnerability, and the issue appears in CISA's catalog of known exploited vulnerabilities, indicating confirmed in-the-wild use. No additional mitigation details beyond the vendor advisory are provided in the source references.

EU & UK References

Vulnerability Data

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

CWE(s)
KEV Date Added
23 May 2022

Related Threats

CVEs Like This One

CVE-2019-0752Same product: Microsoft Internet Explorerboth on KEV
CVE-2018-8653Same product: Microsoft Internet Explorerboth on KEV
CVE-2018-8639Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-1367Same product: Microsoft Internet Explorerboth on KEV
CVE-2019-1429Same product: Microsoft Internet Explorerboth on KEV
CVE-2018-8611Same product: Microsoft Windows 10 1607both on KEV
CVE-2018-8373Same product: Microsoft Internet Explorerboth on KEV
CVE-2020-0674Same product: Microsoft Internet Explorerboth on KEV
CVE-2019-0859Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0703Same product: Microsoft Windows 10 1507both on KEV

Affected Assets

microsoft
internet explorer
10, 11

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References