CVE-2017-0059
KEV PoC ×3massMemory-Content Information Disclosure in Microsoft Internet Explorer 9-11
CISA: Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft Internet Explorer 9 through 11 contain an information disclosure vulnerability that allows a remote attacker to read sensitive information from the browser's process memory. The flaw is triggered when a user simply visits or interacts with a specially crafted website, since no privileges are required and only user interaction is needed for exploitation. An attacker gains access to potentially sensitive data held in browser process memory, which does not by itself allow code execution but can expose information useful for follow-on attacks. Any user running Internet Explorer 9, 10, or 11 on Microsoft platforms is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28, three public proof-of-concept references exist, and EPSS assigns a 62% probability of exploitation within 30 days (99th percentile).
What to do: Apply Microsoft security updates for Internet Explorer per CISA's required action (follow vendor instructions), prioritizing systems where legacy IE is still actively used. Because IE 11 reached end of support in June 2022, migrate remaining IE users to Microsoft Edge or enable IE mode rather than relying on the legacy browser. As an interim measure, warn users not to browse untrusted or attacker-influenced websites with IE, since exploitation requires user interaction with a crafted site.
| Microsoft Internet Explorer | 9 through 11 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.