peter bassill · operator
$ cve CVE-2017-0037 JSON

CVE-2017-0037 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 80.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-18.

Description

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS80.39% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-843
On CISA KEVyes — remediate by 2022-04-18
Public exploityes
Published2017-02-26
Last modified2026-06-17

CISA KEV

NameMicrosoft Edge and Internet Explorer Type Confusion Vulnerability
Added2022-03-28
Due2022-04-18
Vendor / productMicrosoft / Edge and Internet Explorer
Ransomware usenone reported

Affected (9)

VendorProduct
microsoftedge
microsoftinternet explorer
microsoftwindows 10 1507
microsoftwindows 10 1511
microsoftwindows 10 1607
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2012
microsoftwindows server 2016

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD