A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 75.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| Ransomware bonus | +5.00 |
| VPI | 100.00 |
VPI formula vpi-v1
Required Action
Apply updates per vendor instructions.
This CVE is referenced in a KISA security bulletin (Korean only).
| Source | CVSS Version | Base Score | Severity | Vector String | Assessment Date |
|---|---|---|---|---|---|
| NVDNIST | 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H | 04/20/2026 |
| NVDNIST | 2.0 | 7.6 |
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
| AV:N/AC:H/Au:N/C:C/I:C/A:C |
| 04/20/2026 |