Junglewise Threat Intelligence

CVE-2017-0037: Microsoft Edge and Internet Explorer Type Confusion Vulnerability

CVE-2017-0037 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A type confusion vulnerability exists in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll. Remote attackers can execute arbitrary code via crafted CSS token sequences and JavaScript code operating on a TH element.

Affected products

  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 11
  • Microsoft Edge

Timeline

  • 2017-03-14: patched: MSRC advisory published.
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2017-03-01: exploited: Public reports of 0-day exploitation.

Related threats