ZeroHour

CVE-2017-0222

KEVmass

Memory Corruption RCE in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
30%p98
Published
()
KEV added
AI analysis

CVE-2017-0222 is a remote code execution flaw in Microsoft Internet Explorer caused by improper access to objects in memory (CWE-119), which can corrupt memory in a way that allows arbitrary code execution. It is triggered remotely, typically when a user is persuaded to view attacker-controlled web content in Internet Explorer. A successful attack runs code in the context of the current user, so the attacker gains that user's privileges and potentially full control of the workstation if the user has elevated rights. Anyone running affected builds of Internet Explorer is exposed, which historically means the very large base of Windows desktops that shipped with IE. Exploitation is confirmed in the wild — CISA added the CVE to its KEV catalog on 2022-02-25 — while no public proof-of-concept is known and ransomware use is unknown; EPSS estimates a 29.6% chance of exploitation in the next 30 days (98th percentile).

What to do: Apply the Microsoft cumulative security update for Internet Explorer that fixes this issue (released with the April 2017 Patch Tuesday, or any later cumulative IE update) on all Windows systems that still run IE, prioritizing legacy and internet-facing machines. Because CISA's KEV listing in February 2022 shows the flaw was still being exploited years after patching, audit Windows 7/8.1 and Windows Server estates for unpatched IE and migrate users to Microsoft Edge (with IE mode if needed). As interim mitigations, restrict or disable legacy IE, warn users about opening untrusted links, and verify current IE patch levels before patching.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of Windows endpoints (IE was bundled by default on Windows desktops of the era) — Internet Explorer shipped by default on essentially every Windows desktop when the flaw was disclosed, so potential exposure tracks the Windows installed base on the order of hundreds of millions of devices, with the unpatched remainder…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news