CVE-2017-0037
גבוהה 8.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Edge and Internet Explorer Type Confusion Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 80% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-843
מוצרים מושפעים
microsoft: edge; microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 10 1607; microsoft: internet explorer; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: windows server 2012; microsoft: windows server 2016
קישורים
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037 PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037 PatchVendor Advisory
- https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html ExploitThird Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1011 ExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/41454/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42354/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43125/ ExploitThird Party AdvisoryVDB Entry
- https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html ExploitThird Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1011 ExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/41454/ ExploitThird Party AdvisoryVDB Entry