Executive brief
A type confusion vulnerability exists in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll. Remote attackers can execute arbitrary code via crafted CSS token sequences and JavaScript code operating on a TH element.
Affected products
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
- Microsoft Edge
Timeline
- 2017-03-14: patched: MSRC advisory published.
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2017-03-01: exploited: Public reports of 0-day exploitation.