Junglewise Threat Intelligence

CVE-2017-0222: Microsoft Internet Explorer Remote Code Execution Vulnerability

CVE-2017-0222 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-02-25

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Internet Explorer when it improperly accesses objects in memory, leading to memory corruption. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the execution of arbitrary code in the context of the current user.

Affected products

  • Microsoft Internet Explorer 9
  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 11

Timeline

  • 2017-05-12: disclosed: NVD Published Date
  • 2017-05-12: patched: MSRC advisory and patch released
  • 2022-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-25: exploited: Reported as exploited in the wild per CISA KEV catalog entry

Related threats