CVE-2017-0149
KEVmassMemory Corruption RCE in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Memory Corruption Vulnerability
A memory corruption flaw (CWE-119) in Microsoft Internet Explorer mishandles memory when the browser processes web content. An attacker triggers it by luring a user to a specially crafted website, corrupting browser memory in a way that permits remote code execution in the context of the current user or a crash (denial of service). Successful exploitation gives the attacker code execution under the victim's privileges, yielding a foothold in the user's environment, including elevated access if an administrator is browsing. Internet Explorer versions 9 through 11 (per vendor advisory) are affected, with residual exposure concentrated in legacy Windows 7/8.x and Windows Server estates and in the IE11 component still present on Windows 10. The flaw is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-24, and EPSS estimates a ~29% probability of exploitation within 30 days (98th percentile); no public PoC is known.
What to do: Install Microsoft's cumulative security update for Internet Explorer (the fix shipped in the March 2017 Patch Tuesday cumulative IE updates) on legacy Windows 7/8.x/Server hosts, and ensure Windows 10 devices are fully current via cumulative Windows updates. Inventory for legacy Windows machines and servers with unpatched IE, and prioritize migration to Microsoft Edge (using IE Mode only where required) since IE11 is retired. Where IE must remain in use, harden it with attack surface reduction rules and discourage or restrict browsing of untrusted sites in IE.
| Microsoft Internet Explorer | Internet Explorer 9, 10, and 11 (per vendor advisory); fixed by Microsoft's cumulative security updates for IE from March 2017 onward |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H