Microsoft Internet Explorer Vulnerability
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVSS Score
9.8
CRITICAL
Published
20 May 2026 00:00
Modified
N/A
Vendor
Microsoft
Product
Internet Explorer
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-399
Affected Systems
Microsoft
Internet Explorer
Microsoft
Windows Ancillary Function Driver For WinSock
SharePoint
Active Directory Federation Services
SharePoint Server
Windows
DirectX
Internet Explorer
Defender
Microsoft
Office
Visual Basic For Applications (VBA)
External Links
KEV Status
Known Exploited Vulnerability