Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer ProgID arbitrary code execution attempt

IPS-CFWIPS-SWG

2 SIDs: 48782, 200214

First seen
July 2024
Last seen
October 2026

Detects web content that exploits CVE-2019-0541, a flaw in Internet Explorer's VBScript engine that lets crafted ProgID lookups run arbitrary code. The rule matches the Windows script shell ProgID references that public exploits use to reach the vulnerable lookup path.