Executive brief
A memory corruption vulnerability in Microsoft Edge and Internet Explorer allows remote code execution when a user visits a specially crafted website. An attacker could execute arbitrary code in the context of the current user, potentially gaining full administrative rights if the user is logged in with such privileges.
Affected products
- Microsoft Edge
- Microsoft Internet Explorer
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: exploited