Netskope Threat Labs

BROWSER-IE Microsoft Edge scripting engine use after free attempt

IPS-CFWIPS-SWG

1 SID: 46544

First seen
December 2023
Last seen
October 2026

Detects web content that exploits CVE-2018-0946, a use-after-free in Microsoft Edge's scripting engine that can allow code execution. The rule matches the cross-frame eval and data view getter probing that public exploits use to free engine objects while they remain in use.