CVE-2019-0676: Microsoft Internet Explorer Information Disclosure Vulnerability
Medium severity, CVSS 6.5. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 8.1% chance of exploitation in the next 30 days.
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
Affected products
- Microsoft Internet Explorer: version 10 only; version 11 only
Published 2019-03-05. Last modified 2026-06-17.