Researchers detailed how CVE-2019-1367, a remote code execution flaw in Internet Explorer's legacy jscript.dll, was exploited in the wild through a use-after-free condition tied to improper garbage collection of JScript VAR structures. Analysis linked the bug to a broader recurring Internet Explorer JScript vulnerability class that also includes CVE-2018-8653, CVE-2019-1429, and CVE-2020-0674, with evidence that later flaws were variants or incomplete fixes of the same underlying issue. Google Project Zero later cited CVE-2020-0674 as an example of an incompletely patched vulnerability and warned that several 2020 zero-days reused previously known bug classes and exploit techniques.
Traffic and exploit-chain analysis tied successful CVE-2019-1367 exploitation to the Magnitude Exploit Kit, which used a base64-encoded landing page, a second-stage script, and a JScript.Encode payload to force IE8 compatibility mode so the browser would load the vulnerable legacy engine instead of jscript9.dll. Reporting also connected earlier targeting to North Korea-linked activity and open-source reporting associated some exploitation with DarkHotel APT, while later campaigns targeted South Korean users and ultimately delivered ransomware. Microsoft patched the flaw and advised disabling jscript.dll, particularly in environments where legacy compatibility mode could still expose the vulnerable code path.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
JPCERT/CC confirmed attacks on Japanese infrastructure involving the Double Star exploits and again attributed them to DarkHotel APT. The attacks used last.tax-lab[.]net to host exploit code and a backdoor.
Google TAG confirmed that CVE-2018-8653, CVE-2019-1367, and CVE-2020-0674 were JScript vulnerabilities abusing the Enumerator object. This tied the exploited flaws together as part of the same recurring bug class.
Packet captures published by malware-traffic-analysis showed a successful Magnitude Exploit Kit attack exploiting CVE-2019-1367. The analyzed chain used bluegas[.]website to host exploit code and pophot[.]website to host ransomware.
AhnLab reported Magnitude Exploit Kit exploiting CVE-2019-1367 in the wild against South Korean targets. The campaign was described as opportunistic malvertising activity associated with Magnitude EK.
Qihoo 360 reported that DarkHotel APT had switched to exploiting Internet Explorer CVE-2020-0674 and Firefox CVE-2019-17026 in an attack dubbed Double Star.
Project Zero said CVE-2020-0674 was detected as exploited in the wild in January 2020. It described the flaw as another Internet Explorer JScript garbage-collection variant related to CVE-2019-1367.
Microsoft released CVE-2019-1429 in November 2019 to address shortcomings in the CVE-2019-1367 fix and to patch a related variant in the toJSON callback.
Project Zero reported that CVE-2019-1367 was detected as exploited in the wild in September 2019. Google TAG discovered the exploitation and later said the main targets were North Korea or individuals working on North Korea-related issues.
The first in-the-wild exploitation in this Internet Explorer JScript bug class was observed through CVE-2018-8653. Later reporting grouped it with CVE-2019-1367, CVE-2019-1429, and CVE-2020-0674 as closely related garbage-collection flaws.
Microsoft released a patch for the Internet Explorer remote code execution flaw CVE-2019-1367 and advised users to disable jscript.dll because IE8 compatibility mode could still invoke the legacy vulnerable engine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
googleprojectzero.blogspot.com
Open sourceblog.confiant.com
Open sourceblog.confiant.com
Open sourceportal.msrc.microsoft.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.