Skip to content
COOEY

FAIL › dossier

Internet Explorer

PRODUCT

· dossier confidence 40%

Internet Explorer is a discontinued web browser from Microsoft with a catastrophic security track record. It was plagued by critical and high-severity remote code execution and memory corruption vulnerabilities throughout its lifecycle, and is now end-of-life and unsupported.

PROFILE
CategorysoftwareWhat they doInternet Explorer is a web browser developed by Microsoft Corporation, first launched in August 1995.Founded1995 Websitehttps://www.microsoft.com/en-us/internet-explorer ↗
SECURITY POSTURE

Extremely poor; the product is end-of-life and unsupported, with a documented history of critical and high-severity remote code execution, memory corruption, and use-after-free vulnerabilities across its lifecycle.

Notable failures
  • CVE-2019-0752 critical RCE
  • CVE-2019-1367 critical RCE
  • CVE-2010-0806 high RCE on EoL
  • CVE-2013-2551 critical use-after-free
  • CVE-2021-26411 critical memory corruption
  • CVE-2010-3962 high RCE on EoL
Patterns: repeated unpatched RCE via scripting engine memory corruption; use-after-free vulnerabilities enabling remote code execution; memory corruption in JScript/VBScript engines; end-of-life products remaining vulnerable to critical exploits
FAILURE HISTORY · 36
DATEEVENTSEVSUMMARY
2026-05-20 CVE-2010-0806 high Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers.
2021-11-03 CVE-2019-1429 high Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
2022-05-25 CVE-2014-4123 high An unpatched privilege escalation flaw in Microsoft Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website.
2022-05-04 CVE-2014-0322 high A use-after-free vulnerability in Internet Explorer allowed remote attackers to execute code.
2022-03-28 CVE-2015-2419 high A memory corruption flaw in Internet Explorer's JScript engine allowed remote attackers to execute arbitrary code via a malicious website.
2022-03-03 CVE-2013-1347 high Microsoft Internet Explorer's CVE-2013-1347 allows remote code execution via memory corruption, a flaw actively exploited in the wild despite the product being end-of-life.
2022-03-03 CVE-2013-3897 high A use-after-free vulnerability in Internet Explorer allowed remote code execution, and the browser was already end-of-life and unsupported.
2022-01-28 CVE-2014-1776 high A memory corruption flaw in Internet Explorer allowed remote attackers to execute code as the current user.
2021-11-03 CVE-2020-0968 high A memory corruption flaw in Internet Explorer's Scripting Engine allowed remote code execution, and was actively exploited in the wild.
2021-11-03 CVE-2018-8653 high Microsoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution.
2022-05-25 CVE-2014-2817 high A privilege escalation vulnerability in Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website.
2022-05-25 CVE-2015-0071 high A crafted website bypassed Internet Explorer's ASLR protection, enabling remote attackers to execute arbitrary code.
2022-05-25 CVE-2015-2425 high A memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service.
2022-05-24 CVE-2017-0149 high A memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service via a crafted website.
2022-04-13 CVE-2015-2502 high A memory corruption flaw in Internet Explorer allowed remote code execution and was actively exploited in the wild.
2022-03-28 CVE-2016-0189 high A memory corruption flaw in Internet Explorer's JScript and VBScript engines allowed remote code execution via malicious websites.
2022-02-25 CVE-2017-0222 high Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2021-27085 high Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2020-1380 high Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
2021-11-03 CVE-2020-0674 high Microsoft Internet Explorer's Scripting Engine had a memory corruption vulnerability allowing remote code execution.
2025-10-06 CVE-2010-3962 high Uninitialized memory corruption in IE allowed remote code execution.
2025-08-12 CVE-2013-3893 high End-of-life IE allowed remote code execution due to unpatched vulnerabilities
2023-03-30 CVE-2013-3163 high Memory corruption in IE allowed remote code execution
2022-06-08 CVE-2012-4969 high A Microsoft Internet Explorer use-after-free vulnerability allows remote code execution via a crafted website, and is currently being exploited in the wild.
2022-03-28 CVE-2013-2551 critical A Microsoft Internet Explorer use-after-free vulnerability allowed remote code execution via crafted websites and is actively exploited in ransomware attacks.
2022-02-15 CVE-2019-0752 critical Microsoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments.
2021-11-03 CVE-2019-1367 critical A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.
2021-11-03 CVE-2021-26411 critical A memory corruption vulnerability in unsupported Microsoft Internet Explorer allowed exploitation and was actively exploited in the wild, linked to ransomware activity.
2022-05-25 CVE-2013-7331 high An information disclosure vulnerability in Internet Explorer allowed attackers to detect anti-malware applications by querying resources loaded into memory.
2022-05-24 CVE-2016-0162 high An information disclosure vulnerability in Internet Explorer allowed attackers to detect specific files on a user's computer.
2022-05-24 CVE-2017-0210 high Internet Explorer's cross-domain policy enforcement flaw allowed attackers to escalate privileges and access sensitive data.
2022-05-24 CVE-2016-3298 high An information disclosure vulnerability in Internet Explorer's Messaging API allowed attackers to test for file presence on disk.
2022-05-23 CVE-2019-0676 high Microsoft Internet Explorer had an information disclosure vulnerability allowing attackers to test for file presence on disk.
2022-03-28 CVE-2017-0059 high A remote information disclosure vulnerability in Internet Explorer allowed attackers to read sensitive data from process memory via a crafted website.
2026-05-20 CVE-2010-0249 high Microsoft Internet Explorer use-after-free vulnerability (CVE-2010-0249) allows remote code execution on EoL browsers.
2024-07-23 CVE-2012-4792 high Microsoft Internet Explorer's use-after-free vulnerability (CVE-2012-4792) allows remote attackers to execute arbitrary code via a crafted website.
Open questions: Exact founding year of Internet Explorer · Specific HQ location for Internet Explorer development
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:11:55.034965+00:00