ZeroHour

CVE-2017-0059

KEV PoC ×3mass

Memory-Content Information Disclosure in Microsoft Internet Explorer 9-11

CISA: Microsoft Internet Explorer Information Disclosure Vulnerability

CVSS 3.1
4.3 medium
EPSS
62%p99
Published
()
KEV added
AI analysis

Microsoft Internet Explorer 9 through 11 contain an information disclosure vulnerability that allows a remote attacker to read sensitive information from the browser's process memory. The flaw is triggered when a user simply visits or interacts with a specially crafted website, since no privileges are required and only user interaction is needed for exploitation. An attacker gains access to potentially sensitive data held in browser process memory, which does not by itself allow code execution but can expose information useful for follow-on attacks. Any user running Internet Explorer 9, 10, or 11 on Microsoft platforms is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28, three public proof-of-concept references exist, and EPSS assigns a 62% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft security updates for Internet Explorer per CISA's required action (follow vendor instructions), prioritizing systems where legacy IE is still actively used. Because IE 11 reached end of support in June 2022, migrate remaining IE users to Microsoft Edge or enable IE mode rather than relying on the legacy browser. As an interim measure, warn users not to browse untrusted or attacker-influenced websites with IE, since exploitation requires user interaction with a crafted site.

Affected
Microsoft Internet Explorer9 through 11
Estimated exposure
masshundreds of millions of Windows users/devices (IE 9-11 was the built-in Windows browser at the 2017 disclosure and legacy IE installations persist widely) — Internet Explorer 9-11 shipped as the default or built-in browser on hundreds of millions of enterprise and consumer Windows PCs when this flaw was disclosed, and unpatched legacy IE installations remain common in enterprise estates, far…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.