Microsoft Internet Explorer 10 and 11 and Microsoft Edge...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jul 16, 2024
Description
Published by the National Vulnerability Database
Feb 26, 2017
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jul 16, 2024
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
References