Executive brief
A remote code execution vulnerability exists in Microsoft Internet Explorer when it improperly accesses objects in memory, leading to memory corruption. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the execution of arbitrary code in the context of the current user.
Affected products
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
Timeline
- 2017-05-12: disclosed: NVD Published Date
- 2017-05-12: patched: MSRC advisory and patch released
- 2022-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-25: exploited: Reported as exploited in the wild per CISA KEV catalog entry