Executive brief
A remote code execution vulnerability exists in the Microsoft MSHTML engine due to improper input validation. An attacker could exploit this by convincing a user to view specially crafted content, potentially leading to full system compromise.
Affected products
- Microsoft MSHTML engine
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
- Microsoft Office 365 ProPlus
- Microsoft Office Word Viewer
- Microsoft Excel Viewer
Timeline
- 2019-01-08: advisory: MSRC advisory published (based on CVE ID year and bid date)
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed