CVE-2018-0866
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0858, CVE-2018-0859, CVE-2018-0860, and CVE-2018-0861.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 11
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 41.7% (99th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2018-02-15
CVE-2018-0866 at NVD
5 known exploits for CVE-2018-0866
Proof-of-concept code and exploit modules indexed by Sploitus
IE11: Use-after-free in Js::RegexHelper::RegexReplace(CVE-2018-0866)
IE11: Use-after-free in String.lastIndexOf(CVE-2018-0866)
Microsoft IE11 Js::RegexHelper::RegexReplace Use-After-Free
Microsoft Internet Explorer 11 - 'Js::RegexHelper::RegexReplace' Use-After-Free
Microsoft Internet Explorer 11 - Js::RegexHelper::RegexReplace Use-After-Free Exploit