Executive brief
A memory corruption vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. An attacker could exploit this to execute arbitrary code in the context of the current user, typically via a specially crafted website.
Affected products
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
Timeline
- 2018-12-19: disclosed: Initial vulnerability disclosure and patch release by Microsoft.
- 2019-01-03: other: Initial analysis by NIST NVD.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.