CVE-2017-0037
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Access of Resource Using Incompatible Type ('Type Confusion')
IncompleteCommon Consequences
Applicable Platforms
Microsoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type …
VerifiedMicrosoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type Confusion
View Exploit Code →Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution …
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
View Exploit Code →Microsoft Internet Explorer 11 (Windows 7 x86) - …
VerifiedMicrosoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
View Exploit Code →Edge by Microsoft
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*
Internet Explorer by Microsoft
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*