Executive brief
A memory corruption vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. Successful exploitation could allow a remote attacker to execute arbitrary code in the context of the current user, typically via a specially crafted website.
Affected products
- Microsoft Internet Explorer 9, 10, 11
Timeline
- 2019-09-24: disclosed: Initial analysis by NIST
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: other: Publication date listed in advisory