CVE-2021-27085KEV · OVERDUE

Microsoft Internet Explorer Remote Code Execution Vulnerability

High · published March 11, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 92.2th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
5%
Percentile
92.2
In the wild
Confirmed
What it is

🚨 A sneaky flaw in Internet Explorer can let attackers execute code remotely, making it a goldmine for mischief-makers! ⚡ Think of this vulnerability like a hotel receptionist who lets guests access any room without checking their IDs — it opens the door to anyone with bad intentions. Suddenly, all your data could be at risk! An attacker could exploit this vulnerability and gain full control over your system, allowing them to install malware, steal sensitive information, or cause chaos with your files. Picture someone walking into your office and wiping everything clean — absolutely devastating!

Put simply

Think of this vulnerability like a hotel receptionist who lets guests access any room without checking their IDs — it opens the door to anyone with bad intentions. Suddenly, all your data could be at risk! This vulnerability allows remote code execution through Internet Explorer when it fails to properly handle objects in memory. If exploited, it grants attackers the ability to run arbitrary code on the affected system, potentially allowing them to take complete control.

What to do

An attacker could exploit this vulnerability and gain full control over your system, allowing them to install malware, steal sensitive information, or cause chaos with your files. Picture someone walking into your office and wiping everything clean — absolutely devastating! To protect yourself, update Internet Explorer to the latest version immediately. Additionally, consider disabling Active Scripting in your browser settings to add an extra layer of defense. Regularly review your system for any unauthorized changes. 🔒 You've got this! With the right updates and precautions, you'll keep your data safe and sound. 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.05448 · 92.2th percentile
Published
2021-03-11T21:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (1)
ProductVersionsFixed in
microsoft/internet_explorerall versions
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 11 MAR 15:46Z
    Internet Explorer Remote Code Execution Vulnerability
    cvelistv5