CVE-2017-0210
KEVmassCross-Domain Privilege Escalation in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Privilege Escalation Vulnerability
CVE-2017-0210 is a privilege elevation flaw caused by Internet Explorer failing to properly enforce cross-domain policies, breaking the isolation between security zones/domains in the browser. It is triggered when a user views malicious or attacker-controlled web content in Internet Explorer, allowing content from one domain to reach resources that should be restricted to another domain or zone. Successful exploitation lets an attacker access information across those boundaries and gain elevated privileges within the browser context, which is commonly chained with other flaws for fuller compromise. Any user running affected versions of Internet Explorer on Windows is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24), indicating known exploitation in the wild, with a 22.3% EPSS probability of exploitation in the next 30 days (98th percentile).
What to do: Apply Microsoft security updates per vendor instructions (the latest cumulative Internet Explorer security updates on all supported Windows versions still in use), since CISA's required action is to apply updates. Audit your environment for systems still launching IE or embedded WebBrowser/IE-based content, restrict or retire IE usage, and migrate users to a supported modern browser (e.g., Edge, using IE mode only for legacy intranet apps) to reduce exposure.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H