PT-2021-2289 · Microsoft · Internet Explorer+1

Enkiyangkang

+1

·

Published

2021-03-09

·

Updated

2025-12-05

·

CVE-2021-26411

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer versions prior to the fixed version
Description The issue is related to a memory corruption vulnerability in Internet Explorer, which can be exploited by attackers to affect the confidentiality, integrity, and availability of protected information. This vulnerability has been used in real-world incidents, including spear-phishing emails that trick targets into downloading malicious executables. The estimated number of potentially affected devices worldwide is not specified. Technical details about exploitation include the use of external links to fetch remote pages containing exploits. API endpoints and vulnerable parameters or variables are not explicitly mentioned.
Recommendations As a temporary workaround, consider disabling the use of Internet Explorer until a patch is available. Restrict access to external links and attachments from unknown sources to minimize the risk of exploitation. Avoid using Internet Explorer for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Double Free

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01372
CVE-2021-26411

Affected Products

Edge
Internet Explorer