HIGH
CVE-2021-26411
CVSS
8.8
KEV
Description
Internet Explorer Memory Corruption Vulnerability
Summary dbcve.org
CVE-2021-26411 is a memory corruption vulnerability in Internet Explorer that could allow an attacker to execute arbitrary code via a specially crafted webpage. The high CVSS score (8.8) indicates the vulnerability is exploitable and can lead to code execution with user interaction (typically visiting a malicious website).
Mitigation
Apply the Microsoft security update for this vulnerability (KB5003171 or subsequent patches) and consider disabling Internet Explorer if no longer required, as it is deprecated.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
80.77%
Probability of exploitation in next 30 days
99.6th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26411
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26411
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26411
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.