CVE-2017-0037

Confirmed PUBLISHED

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the...

Microsoft Corporation · Internet Browser
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High

At a Glance

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

microsoft java cisa
CVE Published
Feb 26, 2017
Exploitation Reported
Mar 28, 2022
CVSS
8.1 High
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Microsoft Corporation
Internet Browser

Internet Explorer 10 and 11 and Edge

Affected

CVE References

  • 41454 exploit-db.com · Exploit https://www.exploit-db.com/exploits/41454/
  • 43125 exploit-db.com · Exploit https://www.exploit-db.com/exploits/43125/
  • 42354 exploit-db.com · Exploit https://www.exploit-db.com/exploits/42354/
  • 96088 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/96088
  • 1037905 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1037905
Show 4 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.