CVE-2017-0037 KEV EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 80.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-18.
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 80.39% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-843 |
| On CISA KEV | yes — remediate by 2022-04-18 |
| Public exploit | yes |
| Published | 2017-02-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Edge and Internet Explorer Type Confusion Vulnerability |
|---|---|
| Added | 2022-03-28 |
| Due | 2022-04-18 |
| Vendor / product | Microsoft / Edge and Internet Explorer |
| Ransomware use | none reported |
Affected (9)
| Vendor | Product |
|---|---|
| microsoft | edge |
| microsoft | internet explorer |
| microsoft | windows 10 1507 |
| microsoft | windows 10 1511 |
| microsoft | windows 10 1607 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007) | 2017-10-17 |
| exploit-db | Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007) | 2017-07-24 |
| exploit-db | Microsoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type Confusion | 2017-02-24 |
References
- http://www.securityfocus.com/bid/96088
- http://www.securitytracker.com/id/1037905
- http://www.securitytracker.com/id/1037906
- https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1011
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037
- https://www.exploit-db.com/exploits/41454/
- https://www.exploit-db.com/exploits/42354/
- https://www.exploit-db.com/exploits/43125/
- http://www.securityfocus.com/bid/96088
- http://www.securitytracker.com/id/1037905
- http://www.securitytracker.com/id/1037906
- https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1011
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037
- https://www.exploit-db.com/exploits/41454/
- https://www.exploit-db.com/exploits/42354/
- https://www.exploit-db.com/exploits/43125/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0037
→ the Explorer · watch your stack · NVD