Vulnerability record · CVE-2017-0037 · published 26 February 2017
CVE-2017-0037: Microsoft Edge and IE mshtml type confusion enables remote code execution
Microsoft · Edge
Microsoft Internet Explorer 10 and 11 and Microsoft Edge contain a type confusion flaw in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll. A crafted CSS token sequence combined with JavaScript operating on a TH element can corrupt memory and lead to arbitrary code execution. The flaw is remotely reachable and has been exploited in the wild, making it a serious risk for unpatched browsers.
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows remote code execution, is listed in CISA KEV with confirmed exploit references, and has an EPSS score above 0.80, so unpatched systems are at immediate risk.
What it is
Microsoft Internet Explorer 10 and 11 and Microsoft Edge contain a type confusion flaw in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll. A crafted CSS token sequence combined with JavaScript operating on a TH element can corrupt memory and lead to arbitrary code execution. The flaw is remotely reachable and has been exploited in the wild, making it a serious risk for unpatched browsers.
Impact
An attacker can execute arbitrary code in the context of the affected browser process, giving them the ability to run code as the logged-on user. Depending on privileges, this can lead to full system compromise.
Attack surface
Reached remotely over the network, typically by a user visiting a crafted web page or opening malicious content in IE or Edge. The CVSS vector shows no privileges required and no user interaction (PR:N/UI:N), though in practice delivery usually relies on the victim loading attacker-controlled content.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-28, and multiple references are tagged as Exploit, including Exploit-DB entries and a Project Zero issue. EPSS is very high at 0.804 (99.6th percentile), indicating active exploitation is likely.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) to all affected IE 10, IE 11 and Edge installations.
- Retire or isolate Internet Explorer and legacy Edge where patching is not possible, and enforce a modern supported browser.
- Block or restrict access to untrusted web content and disable legacy browser rendering modes in enterprise configurations.
- Monitor for and remove unpatched browser versions from endpoints using software inventory and vulnerability scanning.
Detection
- Hunt for browser processes (iexplore.exe, MicrosoftEdge.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for normal browsing.
- Monitor for crashes in mshtml.dll, especially involving Layout::MultiColumnBoxBuilder, as a possible exploitation attempt.
- Review proxy and DNS logs for known exploit-hosting domains and for traffic to sites delivering the crafted CSS/JavaScript payloads.
- Alert on suspicious file writes or registry changes originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0037 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Edge and Internet Explorer Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0037 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0037), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.