CVE-2021-27085
KEVmassMemory Corruption RCE in Microsoft Internet Explorer (MSHTML)
CISA: Microsoft Internet Explorer Remote Code Execution Vulnerability
CVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer's HTML rendering engine (MSHTML), caused by improper handling of objects in memory. Exploitation requires user interaction: an attacker must lure a user into viewing attacker-controlled content, such as a malicious website opened in Internet Explorer or HTML rendered inside an application that uses the Windows MSHTML component. If successful, the attacker executes arbitrary code with the privileges of the current user, and the CVSS changed-scope metric reflects that the code can run in the host application rather than only inside the browser. Any Windows system with Internet Explorer components is affected; per CISA the affected product is Microsoft Internet Explorer, with specific version ranges listed in Microsoft's advisory. The flaw was fixed in Microsoft's March 2021 Patch Tuesday, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (EPSS 5.4%, 92nd percentile; no public PoC known; ransomware use: unknown).
What to do: Apply the Microsoft fixes released in the March 2021 Patch Tuesday, per vendor instructions, prioritizing multi-user and internet-exposed systems, and verify patch status across the estate. Because exploitation requires viewing attacker-controlled content, restrict legacy IE/MSHTML usage (e.g., applications embedding the WebBrowser control) to trusted content, and confirm affected builds and update paths in Microsoft's advisory.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Internet Explorer Remote Code Execution Vulnerability
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L