Netskope Threat Labs

BROWSER-IE Microsoft Windows Scripting Engine memory corruption attempt

IPS-CFWIPS-SWG

5 SIDs: 63865, 170080, 170081, 200353, 200354

Detects web content that exploits CVE-2024-38178, memory corruption in Microsoft's scripting engine that can allow code execution. The rule matches the typed array grooming that public exploits use to corrupt memory, and Microsoft shipped the fix after confirming exploitation in the wild.