CVE-2017-0059: medium-severity vulnerability in Microsoft Corporation Internet Explorer
Published · Updated
75Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 4.3epss 62%
from disclosure to weapon3 days
Published on NVDMar 17
1st PoC+3d
CISA KEV+1837d
exploitation probability
62%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2022-04-18
Apply updates per vendor instructions.
In short
Internet Explorer 9 through 11 can leak sensitive information from a computer's memory when visiting a malicious website. An attacker can use this to steal private data without the user knowing.
Technical detail
A remote attacker can craft a malicious web page that exploits an information disclosure vulnerability in Internet Explorer 9-11 to read sensitive data from the target process's memory space. The attack requires user interaction (visiting the malicious site) and affects the confidentiality of process memory contents.
Summary generated and translated by AI from the official description.
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.