Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer MSHTML CTreePos remote code execution attempt

IPS-SWG

1 SID: 58183

Detects web content that exploits CVE-2021-33742, an out-of-bounds write in Internet Explorer's MSHTML engine that can allow code execution. The rule matches the oversized innerHTML assignments that public exploits use to corrupt the tree position structures, and the flaw saw targeted exploitation before the June 2021 fix.