CVE-2021-26411: Internet Explorer mshtml use-after-free

In January of this year, Google and Microsoft respectively published blogs revealing attacks on security researchers by an APT group from NK[1][2]. A vulnerability in Internet Explorer used in this attack was fixed as CVE-2021-26411 in Microsoft’s Patch Tuesday this month[3]. The vulnerability is triggered when users of the affected version of Internet Explorer access a malicious link constructed by attackers, causing remote code execution. Root cause analysis The POC which can trigger the vulnerability is shown below: ...

March 12, 2021 · 7 min · iamelli0t