PT-2021-2289 · Microsoft · Internet Explorer+1
Enkiyangkang
+1
·
Published
2021-03-09
·
Updated
2025-12-05
·
CVE-2021-26411
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions prior to the fixed version
Description
The issue is related to a memory corruption vulnerability in Internet Explorer, which can be exploited by attackers to affect the confidentiality, integrity, and availability of protected information. This vulnerability has been used in real-world incidents, including spear-phishing emails that trick targets into downloading malicious executables. The estimated number of potentially affected devices worldwide is not specified. Technical details about exploitation include the use of external links to fetch remote pages containing exploits. API endpoints and vulnerable parameters or variables are not explicitly mentioned.
Recommendations
As a temporary workaround, consider disabling the use of Internet Explorer until a patch is available. Restrict access to external links and attachments from unknown sources to minimize the risk of exploitation. Avoid using Internet Explorer for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Double Free
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edge
Internet Explorer