ZeroHour

CVE-2017-0037

KEV PoC ×5mass

Type Confusion RCE in Microsoft Internet Explorer and Edge

CISA: Microsoft Edge and Internet Explorer Type Confusion Vulnerability

CVSS 3.1
8.1 high
EPSS
80%p100
Published
()
KEV added
AI analysis

CVE-2017-0037 is a type confusion flaw (CWE-843) in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, located in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function of mshtml.dll. It is triggered when the browser processes a crafted Cascading Style Sheets token sequence combined with JavaScript that operates on a TH (table header) element, typically delivered via a malicious or compromised web page. An attacker who successfully exploits it can execute arbitrary code in the context of the browser process. Any user running the affected legacy Microsoft browsers is exposed, which historically meant most Windows desktops. The flaw was publicly disclosed via Google Project Zero after a 90-day deadline passed, public proof-of-concept exploits are available, and it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), confirming in-the-wild exploitation.

What to do: Apply Microsoft security updates per vendor instructions (the flaw was addressed in Microsoft's March 2017 Patch Tuesday, which followed the Project Zero disclosure), prioritizing systems in CISA KEV scope. Inventory for any hosts still running IE 10/11 or legacy (pre-Chromium) Edge and retire or isolate them, as legacy Microsoft browsers are end-of-life. As an interim mitigation, avoid using affected browsers for untrusted web content, since exploitation requires rendering attacker-crafted CSS/JavaScript.

Affected
microsoft Internet Explorer10, 11
microsoft Edge
Estimated exposure
massHundreds of millions of Windows endpoints (IE 11 and legacy Edge were bundled with Windows 7/8.1/10) — Internet Explorer 10/11 and legacy Edge shipped by default with Windows releases that collectively ran on well over a billion devices, so the plausible install base is in the hundreds of millions, even though active legacy-browser usage…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

CISA Known Exploited Vulnerability
Affected
Microsoft Edge and Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
edge, internet explorer
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news