Skip to content
COOEY

FAIL › dossier

Edge and Internet Explorer

PRODUCT

· dossier confidence 20%

Microsoft Edge is a Chromium-based web browser with legacy IE Mode compatibility, but its history includes critical RCE vulnerabilities in its legacy engine exploited in ransomware. The company has shifted to a 2-week release cycle for faster patching of modern components.

PROFILE
CategoryWeb BrowserWhat they doMicrosoft Edge is a web browser built on the Chromium open-source project, featuring an IE Mode for legacy site compatibility and deep integration with Microsoft 365 services. Websitehttps://www.microsoft.com/edge ↗
SECURITY POSTURE

Microsoft Edge has a mixed security track record, with critical RCE vulnerabilities in its legacy mshtml.dll engine exploited in ransomware attacks, though it benefits from Chromium's modern security model and frequent update cycles.

Notable failures
  • CVE-2017-0037 RCE in mshtml.dll
  • CVE-2020-0878 critical RCE exploited in ransomware
Patterns: repeated RCE in legacy Trident engine; memory corruption in edge rendering
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-28 CVE-2017-0037 high A type confusion vulnerability in Microsoft Edge and Internet Explorer's mshtml.dll allowed remote code execution.
2021-11-03 CVE-2020-0878 critical Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.
Open questions: Current patching cadence for Edge/IE · Status of Internet Explorer support lifecycle
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:52:51.329937+00:00