---
id: CVE-2019-0752
title: >-
  A remote code execution vulnerability exists in the way that the scripting
  engine handles objects in memory in Internet Explorer, aka 'Scripting Engine
  Memory Corruption Vulnerability'
summary: >-
  A remote code execution vulnerability exists in the way that the scripting
  engine handles objects in memory in Internet Explorer, aka 'Scripting Engine
  Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739,
  CVE-2019-…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-843
  - CWE-843
vendor: microsoft
product: internet_explorer
affected:
  - internet_explorer = 11
  - internet_explorer = 10
published: '2019-04-09'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-0752'
references:
  - url: >-
      http://packetstormsecurity.com/files/153078/Microsoft-Internet-Explorer-Windows-10-1809-17763.316-Memory-Corruption.html
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0752
    label: secure@microsoft.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-19-359/'
    label: secure@microsoft.com
  - url: >-
      http://packetstormsecurity.com/files/153078/Microsoft-Internet-Explorer-Windows-10-1809-17763.316-Memory-Corruption.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0752
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-19-359/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0752
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.81551
epssPercentile: 0.99634
kev: true
kevDateAdded: '2022-02-15'
kevDueDate: '2022-08-15'
kevRansomware: true
exploited: true
exploitAvailable: true
zeroDay: true
ingestedAt: '2026-08-12T05:52:06.995Z'
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/edxsh/CVE-2019-0752'
  checkedAt: '2026-09-21T15:23:39.609Z'
---

## Overview

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.

## Affected

- `internet_explorer = 11`
- `internet_explorer = 10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
