Executive brief
A memory corruption vulnerability exists in Microsoft Internet Explorer due to a use-after-free (CWE-416) error. An attacker can exploit this by convincing a user to visit a specially crafted website, potentially leading to remote code execution.
Affected products
- Microsoft Internet Explorer 11
- Microsoft Edge
- Microsoft Windows 10
- Microsoft Windows 7
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: patched: Microsoft released security updates to address this vulnerability.