cbcvebase.
CVE-2021-34448
published 2021-07-16

CVE-2021-34448: Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
30.67%
98.0th percentile
Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1900310.0.10240.19003
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.453010.0.14393.4530
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.206110.0.17763.2061
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.167910.0.18363.1679
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.111010.0.19041.1110
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.111010.0.19042.1110
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.111010.0.19043.1110
microsoftwindows_7>= 6.1.0 < 6.1.7601.256616.1.7601.25661
microsoftwindows_7>= 6.1.0 < 1.0011.001
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.256616.1.7601.25661
microsoftwindows_7_service_pack_1>= 6.1.0 < 1.0011.001
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.200696.3.9600.20069
microsoftwindows_8.1>= 6.3.0 < 1.0011.001
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.256616.1.7601.25661
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 1.0011.001
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.234096.2.9200.23409
microsoftwindows_server_2012>= 6.2.0 < 1.0011.001
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.200696.3.9600.20069
microsoftwindows_server_2012_r2>= 6.3.0 < 1.0011.001
microsoftwindows_server_2016>= 10.0.0 < 10.0.14393.453010.0.14393.4530
microsoftwindows_server_2019>= 10.0.0 < 10.0.17763.206110.0.17763.2061
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_1909

Detection & IOCsextracted from sources · hover to see the quote

snort
57890, 57891, 57894 - 57897 and 57906 - 57910
sigma
1011040 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2021-34448)
  • CVE-2021-34448 is triggered when a user opens a specially crafted file delivered via email attachment or a compromised website; monitor for suspicious file opens originating from email clients or browsers invoking the scripting engine.
  • Use Trend Micro Deep Security / Vulnerability Protection rule 1011040 to detect exploitation attempts against the Internet Explorer Scripting Engine for CVE-2021-34448.
  • CVE-2021-34448 was confirmed as being actively exploited in the wild at the time of the July 2021 Patch Tuesday release; prioritize detection and patching accordingly.
  • ·The Talos Snort SIDs (57890, 57891, 57894–57897, 57906–57910) are listed together for CVE-2021-34448 and related July 2021 Patch Tuesday vulnerabilities; individual SID-to-CVE mapping is not broken out in the source.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
cvelistv56.8MEDIUM
vulncheck6.8MEDIUM
cisa8.8HIGH
vendor_msrc6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.