Aller au contenu
Appaloosa Scout
HIGH 8.1 KEV

CVE-2017-0037

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

CVSS v3 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2022-03-28
Deadline remédiation
2022-04-18
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
microsoft edge Android cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*
microsoft edge iOS cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗