← לוח פגיעויות

CVE-2017-0037

גבוהה 8.1 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Edge and Internet Explorer Type Confusion Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

מדדים

CVSS 3.1
8.1 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
80% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-843

מוצרים מושפעים

microsoft: edge; microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 10 1607; microsoft: internet explorer; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: windows server 2012; microsoft: windows server 2016

קישורים