Executive brief
A remote code execution vulnerability exists in Microsoft Internet Explorer's scripting engine due to improper handling of objects in memory. An attacker could exploit this memory corruption to execute arbitrary code in the context of the current user, typically by enticing a user to visit a specially crafted website.
Affected products
- Microsoft Internet Explorer 10, 11
Timeline
- 2019-11-12: disclosed: MSRC advisory published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.