Junglewise Threat Intelligence

CVE-2021-27085: Microsoft Internet Explorer Remote Code Execution Vulnerability

CVE-2021-27085 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows 10, Microsoft Internet Explorer, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 11 contains an unspecified vulnerability that allows for remote code execution when a user visits a specially crafted website. The vulnerability is known to be exploited in the wild and affects various versions of Windows 10 and Windows Server 2019.

Affected products

  • Microsoft Internet Explorer 11 11
  • Microsoft Windows 10 1803, 1809, 1909, 2004, 20H2
  • Microsoft Windows Server 2019 -

Timeline

  • 2021-03-19: disclosed: Initial analysis by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: patched: Vendor advisory and patch information published by Microsoft
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats