Junglewise Threat Intelligence

CVE-2017-0149: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2017-0149 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 9 through 11 contains a memory corruption vulnerability (out-of-bounds write) when processing crafted websites. This flaw allows remote attackers to execute arbitrary code or cause a denial-of-service condition.

Affected products

  • Microsoft Internet Explorer 9 through 11

Timeline

  • 2017-03-16: disclosed: NVD Published Date
  • 2017-03-17: patched: MSRC advisory and patch information available
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-24: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats