HIGH

CVE-2021-33742

Microsoft Windows 10 1507 2021-06-08 CVSS v3.1
CVSS
7.5
KEV

Description

Windows MSHTML Platform Remote Code Execution Vulnerability

Summary dbcve.org

This is a Remote Code Execution vulnerability in the Windows MSHTML platform (the rendering engine also known as Trident, used by Internet Explorer and embedded in certain Windows components). The 7.5 CVSS indicates it can be exploited remotely without authentication to execute arbitrary code.

Mitigation

Apply the Microsoft security update KB5003635 (or subsequent relevant patch) for CVE-2021-33742, or disable/limit MSHTML/Internet Explorer rendering components in enterprise environments where feasible.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

59.41%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE