Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer VBScript toString redim array use after free attempt

IPS-SWG

1 SID: 39680

First seen
February 2022
Last seen
October 2026

Detects web content that exploits CVE-2016-0189, a use-after-free in Internet Explorer's VBScript engine triggered through string conversion and array redimensioning that can allow code execution. The rule matches the toString override and ReDim sequencing that public exploits use to free objects while they remain in use.