References https://www.sweeterthandespair.com/microsoft-ie-mshtml-reuse-code-execution-vulnerability-after-cdwnbindinfo-object-release.html https://www.linuxidc.com/Linux/2012-12/77140.htm https://www.hkcert.org/tc/security-bulletin/microsoft-internet-explorer-cdwnbindinfo-use-after-free-vulnerability https://www.exploit-db.com/exploits/23754 https://www.hkcert.org/security-bulletin/microsoft-internet-explorer-cdwnbindinfo-use-after-free-vulnerability https://www.reddit.com/r/netsec/comments/15maz7/new_internet_explorer_0day_coming/ https://www.sweeterthandespair.com/tag/ie
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages DisclosurePoCCVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass(CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行