Executive brief
A remote code execution vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. An attacker can exploit this by hosting a specially crafted website or embedding a malicious ActiveX control in an Office document, potentially gaining full user rights or administrative control.
Affected products
- Microsoft Internet Explorer
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed