Vulnerability record · CVE-2021-26411 · published 11 March 2021
CVE-2021-26411: Microsoft Internet Explorer and Edge use-after-free memory corruption
Microsoft · Edge
CVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected product. Successful exploitation can corrupt memory in a way that leads to code execution in the browser context, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Description
Internet Explorer Memory Corruption Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Automated analysis
critical priorityIt is in CISA's KEV catalog with known ransomware use and a very high EPSS score, so it is being exploited in the wild and requires urgent patching.
What it is
CVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected product. Successful exploitation can corrupt memory in a way that leads to code execution in the browser context, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Impact
An attacker who triggers the flaw can corrupt memory and potentially execute code in the context of the affected browser, giving control over the browsing session and a foothold on the host. The CVSS vector rates confidentiality low but integrity high, consistent with an attacker modifying or controlling data rather than only reading it.
Attack surface
The vector is network-reachable with no privileges required, but user interaction is required (UI:R), meaning a victim must open a crafted page or content in the affected browser. No authentication is needed to reach the vulnerable code.
Exploitation
CVE-2021-26411 is in CISA's KEV catalog (added 2021-11-03) with known ransomware campaign use, and EPSS gives a 30-day probability of about 0.81 (99.6th percentile), indicating observed exploitation and high likelihood of continued targeting.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2021-26411 as the first action.
- Retire or disable Internet Explorer where possible and enforce a modern supported browser.
- Restrict or block untrusted web content and legacy browser rendering paths in line with CISA KEV required action.
- Track KEV remediation deadlines and confirm all affected endpoints are patched.
- Reduce exposure by limiting browsing of untrusted sites on systems that still run the affected browsers.
Detection
- Hunt for browser crashes or memory corruption events tied to Internet Explorer or Edge processes.
- Monitor for suspicious child processes spawned by iexplore.exe or msedge.exe, a common post-exploitation pattern.
- Review proxy and DNS logs for access to known exploit-hosting or malicious domains around the time of browser activity.
- Check endpoint telemetry for exploitation artifacts such as unusual script or shellcode execution following a browser page load.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-26411 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Internet Explorer Memory Corruption Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26411 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26411 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26411 | US Government Resource |
Track CVE-2021-26411 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.