CVE detail
CVE-2021-34480
Scripting Engine Memory Corruption Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs
Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]
newssecurityaffairs.comJul 30, 2023, 4:38 PM ets. The hidden malware residing in the documents exploited a vulnerability in the browser's JScript engine, tracked as CVE-2022-41128. Microsoft patches actively exploited Internet Explorer flaw Microsoft patches Internet Explorer zero-day under active attack Microsoft will stop supporting Internet Explorer in 2021 TAG attributed the attacks to APT37,
newswww.itpro.comDec 8, 2022, 10:59 AMGoogle’s Threat Analysis Group (TAG) has shared technical details on an Internet Explorer zero-day vulnerability exploited in attacks by North Korean hacking group APT37.
newswww.securityweek.comDec 7, 2022, 8:22 PM- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34480portal.msrc.microsoft.com
No excerpt available.
Vendor Advisoryportal.msrc.microsoft.comAug 12, 2021, 6:15 PM - http://packetstormsecurity.com/files/164121/Internet-Explorer-JIT-Optimization-Memory-Corruption.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comAug 12, 2021, 6:15 PM - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34480msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comAug 12, 2021, 6:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-22049CVSS 7.8 · High
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-22026CVSS 8.8 · High
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2021-43215CVSS 9.8 · Critical
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
- CVE-2021-26435CVSS 8.1 · High
Windows Scripting Engine Memory Corruption Vulnerability
- CVE-2021-26419CVSS 7.5 · High
Scripting Engine Memory Corruption Vulnerability
- CVE-2021-24083CVSS 7.8 · High
Windows Address Book Remote Code Execution Vulnerability