Executive brief
A remote code execution vulnerability exists in Microsoft Internet Explorer's scripting engine due to improper handling of objects in memory. An attacker could exploit this memory corruption (specifically a use-after-free) to execute arbitrary code in the context of the current user.
Affected products
- Microsoft Internet Explorer 11
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 9
Timeline
- 2020-01-17: disclosed: Initial advisory release by Microsoft
- 2020-02-11: patched: Security updates released by Microsoft
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog