The vulnerability exists in the VBScript engine and how it handles memory objects. It will also affect IE11, even though the compatibility tag for IE10 is no longer supported. The attack came via a Word document making use of OLE autolink objects to retrieve the exploit and shellcode from a remote server. Microsoft has released a patch for this vulnerability, and we strongly advise to apply it, as it is just a matter of time before other threat actors start leveraging this new opportunity in exploit campaigns.”]
Source: https://blog.malwarebytes.com/threat-analysis/2018/05/internet-explorer-zero-day-browser-attack/