Junglewise Threat Intelligence

CVE-2021-26411: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2021-26411 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2012, Microsoft Windows 8.1, Microsoft Edge, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 7, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in Microsoft Internet Explorer due to a use-after-free (CWE-416) error. An attacker can exploit this by convincing a user to visit a specially crafted website, potentially leading to remote code execution.

Affected products

  • Microsoft Internet Explorer 11
  • Microsoft Edge
  • Microsoft Windows 10
  • Microsoft Windows 7
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: patched: Microsoft released security updates to address this vulnerability.

Related threats