Junglewise Threat Intelligence

CVE-2017-0059: Microsoft Internet Explorer Information Disclosure Vulnerability

CVE-2017-0059 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted website. This information disclosure vulnerability occurs when the browser fails to properly handle objects in memory.

Affected products

  • Microsoft Internet Explorer 9 through 11

Timeline

  • 2017-03-14: advisory: MSRC advisory published (based on reference URL)
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: disclosed: NVD publication date
  • 2017-03-14: patched: Microsoft released security updates to address the vulnerability
  • exploited: Reported as exploited in the wild and listed in CISA KEV catalog.

Related threats