CVE-2017-0037: Microsoft Edge and Internet Explorer Type Confusion Vulnerability
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
Other sources
Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0037?
CVE-2017-0037 is rated as critical, allowing attackers to execute arbitrary code remotely.
How do I fix CVE-2017-0037?
To fix CVE-2017-0037, users should apply the latest security updates provided by Microsoft for Internet Explorer and Edge.
Which software versions are affected by CVE-2017-0037?
CVE-2017-0037 affects Microsoft Internet Explorer 10 and 11 as well as certain versions of Microsoft Edge.
Can CVE-2017-0037 be exploited through web pages?
Yes, CVE-2017-0037 can be exploited by attackers through specially crafted web pages.
What are the risks associated with not addressing CVE-2017-0037?
Failing to address CVE-2017-0037 could lead to unauthorized remote code execution, compromising system security.