Description
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Microsoft Corporation / Internet ExplorerInternet Explorer 9 through 11 – Internet Explorer 9 through 11
References
- VENDOR_ADVISORYhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0059
- MISChttp://www.securityfocus.com/bid/96645
- EXPLOIThttps://www.exploit-db.com/exploits/43125/
- EXPLOIThttps://www.exploit-db.com/exploits/41661/
- EXPLOIThttps://www.exploit-db.com/exploits/42354/
- MISChttp://www.securitytracker.com/id/1038008