CVE-2017-0059
בינונית 4.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 62% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
microsoft: internet explorer; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows server 2012; microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 10 1607; microsoft: windows 7; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: windows server 2016
קישורים
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0059 PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0059 PatchVendor Advisory
- https://www.exploit-db.com/exploits/41661/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42354/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43125/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41661/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42354/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43125/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/96645 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038008 Broken LinkThird Party AdvisoryVDB Entry