Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 8.8epss 74%
from disclosure to weapon94 days
Published on NVDMar 11
1st PoC+94d
metasploitMar 6
CISA KEV+3304d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-04-18
Apply updates per vendor instructions.
In short
Internet Explorer versions 6-10 have a flaw where the browser can access memory that has been freed, allowing attackers to run malicious code through a specially crafted website. This happens because the browser doesn't properly track when an object is deleted.
Technical detail
Use-after-free vulnerability in MSHTML engine affecting IE 6-10; remote attacker can craft HTML/JavaScript that triggers dereferencing of freed memory objects, leading to code execution in the browser context. Requires user to visit malicious website; no authentication or user interaction beyond visiting the site needed.
Summary generated and translated by AI from the official description.
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.