CVE Database
/

CVE-2017-0037

Back to search

CVE-2017-0037

Published: Feb 26, 2017

Modified: Oct 21, 2025

PUBLISHED

Description

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

VendorProductVersions

Microsoft Corporation

Internet Browser

affected
Internet Explorer 10 and 11 and Edge

References

96088
vdb-entry
x_refsource_BID
41454
exploit
x_refsource_EXPLOIT-DB
43125
exploit
x_refsource_EXPLOIT-DB
1037905
vdb-entry
x_refsource_SECTRACK
42354
exploit
x_refsource_EXPLOIT-DB
1037906
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now