CVE-2021-26419CriticalCVSS 6.4

Scripting Engine Memory Corruption Vulnerability

Published
May 11, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked "safe for initialization" in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability.

🎯 Affected products30

  • Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 1803 for ARM64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems
  • Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems
  • Internet Explorer 11 on Windows 10 Version 2004 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 2004 for ARM64-based Systems
  • Internet Explorer 11 on Windows 10 Version 2004 for x64-based Systems
  • Internet Explorer 11 on Windows 10 Version 20H2 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 Version 20H2 for ARM64-based Systems
  • Internet Explorer 11 on Windows 10 for 32-bit Systems
  • Internet Explorer 11 on Windows 10 for x64-based Systems
  • Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
  • Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
  • Internet Explorer 11 on Windows 8.1 for 32-bit systems
  • Internet Explorer 11 on Windows 8.1 for x64-based systems
  • Internet Explorer 11 on Windows RT 8.1
  • Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Internet Explorer 11 on Windows Server 2012
  • Internet Explorer 11 on Windows Server 2012 R2
  • Internet Explorer 11 on Windows Server 2016
  • Internet Explorer 11 on Windows Server 2019
  • Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
  • Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2

✅ Remediation

KB5003197 (Security Update) — fixed build 10.0.14393.4401 KB5003210 (Monthly Rollup) — fixed build 6.0.6003.21117 KB5003165 (IE Cumulative) — fixed build 6.0 KB5003174 (Security Update) — fixed build 10.0.17134.2207 KB5003171 (Security Update) — fixed build 10.0.17763.1935 KB5003169 (Security Update) — fixed build 10.0.18363.1556 KB5003173 (Security Update) — fixed build 10.0.19041.982 KB5003172 (Security Update) — fixed build 10.0.10240.18931 KB5003233 (Monthly Rollup) — fixed build 6.1.7601.24597 KB5003165 (IE Cumulative) — fixed build 6.1 KB5003209 (Monthly Rollup) — fixed build 6.3.9600.20017 KB5003165 (IE Cumulative) — fixed build 6.3.9600.20016 KB5003208 (Monthly Rollup) — fixed build 6.2.9200.23347 KB5003165 (IE Cumulative) — fixed build 6.2

🔗 References (20)