FAIL › dossier
Internet Explorer
PRODUCT· dossier confidence 40%
Internet Explorer is a discontinued web browser from Microsoft with a catastrophic security track record. It was plagued by critical and high-severity remote code execution and memory corruption vulnerabilities throughout its lifecycle, and is now end-of-life and unsupported.
PROFILE
CategorysoftwareWhat they doInternet Explorer is a web browser developed by Microsoft Corporation, first launched in August 1995.Founded1995
Websitehttps://www.microsoft.com/en-us/internet-explorer ↗
SECURITY POSTURE
Extremely poor; the product is end-of-life and unsupported, with a documented history of critical and high-severity remote code execution, memory corruption, and use-after-free vulnerabilities across its lifecycle.
Notable failures
- CVE-2019-0752 critical RCE
- CVE-2019-1367 critical RCE
- CVE-2010-0806 high RCE on EoL
- CVE-2013-2551 critical use-after-free
- CVE-2021-26411 critical memory corruption
- CVE-2010-3962 high RCE on EoL
Patterns: repeated unpatched RCE via scripting engine memory corruption; use-after-free vulnerabilities enabling remote code execution; memory corruption in JScript/VBScript engines; end-of-life products remaining vulnerable to critical exploits
FAILURE HISTORY · 36
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-20 | CVE-2010-0806 | high | Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers. |
| 2021-11-03 | CVE-2019-1429 | high | Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild. |
| 2022-05-25 | CVE-2014-4123 | high | An unpatched privilege escalation flaw in Microsoft Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website. |
| 2022-05-04 | CVE-2014-0322 | high | A use-after-free vulnerability in Internet Explorer allowed remote attackers to execute code. |
| 2022-03-28 | CVE-2015-2419 | high | A memory corruption flaw in Internet Explorer's JScript engine allowed remote attackers to execute arbitrary code via a malicious website. |
| 2022-03-03 | CVE-2013-1347 | high | Microsoft Internet Explorer's CVE-2013-1347 allows remote code execution via memory corruption, a flaw actively exploited in the wild despite the product being end-of-life. |
| 2022-03-03 | CVE-2013-3897 | high | A use-after-free vulnerability in Internet Explorer allowed remote code execution, and the browser was already end-of-life and unsupported. |
| 2022-01-28 | CVE-2014-1776 | high | A memory corruption flaw in Internet Explorer allowed remote attackers to execute code as the current user. |
| 2021-11-03 | CVE-2020-0968 | high | A memory corruption flaw in Internet Explorer's Scripting Engine allowed remote code execution, and was actively exploited in the wild. |
| 2021-11-03 | CVE-2018-8653 | high | Microsoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution. |
| 2022-05-25 | CVE-2014-2817 | high | A privilege escalation vulnerability in Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website. |
| 2022-05-25 | CVE-2015-0071 | high | A crafted website bypassed Internet Explorer's ASLR protection, enabling remote attackers to execute arbitrary code. |
| 2022-05-25 | CVE-2015-2425 | high | A memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service. |
| 2022-05-24 | CVE-2017-0149 | high | A memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service via a crafted website. |
| 2022-04-13 | CVE-2015-2502 | high | A memory corruption flaw in Internet Explorer allowed remote code execution and was actively exploited in the wild. |
| 2022-03-28 | CVE-2016-0189 | high | A memory corruption flaw in Internet Explorer's JScript and VBScript engines allowed remote code execution via malicious websites. |
| 2022-02-25 | CVE-2017-0222 | high | Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-27085 | high | Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-1380 | high | Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-0674 | high | Microsoft Internet Explorer's Scripting Engine had a memory corruption vulnerability allowing remote code execution. |
| 2025-10-06 | CVE-2010-3962 | high | Uninitialized memory corruption in IE allowed remote code execution. |
| 2025-08-12 | CVE-2013-3893 | high | End-of-life IE allowed remote code execution due to unpatched vulnerabilities |
| 2023-03-30 | CVE-2013-3163 | high | Memory corruption in IE allowed remote code execution |
| 2022-06-08 | CVE-2012-4969 | high | A Microsoft Internet Explorer use-after-free vulnerability allows remote code execution via a crafted website, and is currently being exploited in the wild. |
| 2022-03-28 | CVE-2013-2551 | critical | A Microsoft Internet Explorer use-after-free vulnerability allowed remote code execution via crafted websites and is actively exploited in ransomware attacks. |
| 2022-02-15 | CVE-2019-0752 | critical | Microsoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments. |
| 2021-11-03 | CVE-2019-1367 | critical | A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments. |
| 2021-11-03 | CVE-2021-26411 | critical | A memory corruption vulnerability in unsupported Microsoft Internet Explorer allowed exploitation and was actively exploited in the wild, linked to ransomware activity. |
| 2022-05-25 | CVE-2013-7331 | high | An information disclosure vulnerability in Internet Explorer allowed attackers to detect anti-malware applications by querying resources loaded into memory. |
| 2022-05-24 | CVE-2016-0162 | high | An information disclosure vulnerability in Internet Explorer allowed attackers to detect specific files on a user's computer. |
| 2022-05-24 | CVE-2017-0210 | high | Internet Explorer's cross-domain policy enforcement flaw allowed attackers to escalate privileges and access sensitive data. |
| 2022-05-24 | CVE-2016-3298 | high | An information disclosure vulnerability in Internet Explorer's Messaging API allowed attackers to test for file presence on disk. |
| 2022-05-23 | CVE-2019-0676 | high | Microsoft Internet Explorer had an information disclosure vulnerability allowing attackers to test for file presence on disk. |
| 2022-03-28 | CVE-2017-0059 | high | A remote information disclosure vulnerability in Internet Explorer allowed attackers to read sensitive data from process memory via a crafted website. |
| 2026-05-20 | CVE-2010-0249 | high | Microsoft Internet Explorer use-after-free vulnerability (CVE-2010-0249) allows remote code execution on EoL browsers. |
| 2024-07-23 | CVE-2012-4792 | high | Microsoft Internet Explorer's use-after-free vulnerability (CVE-2012-4792) allows remote attackers to execute arbitrary code via a crafted website. |
DOSSIER SOURCES
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- Dell Technologies (DELL) Company Profile & Description · stockanalysis.com
- Internet - Wikipedia · en.wikipedia.org
- What is the latest version of Internet Explorer? · www.whatismybrowser.com
- World Wide Web - Wikipedia · en.wikipedia.org
- Internet - Wikipedia · en.wikipedia.org
Open questions: Exact founding year of Internet Explorer · Specific HQ location for Internet Explorer development
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:11:55.034965+00:00