Remote Code Execution Vulnerability in Microsoft Browsers
CVE-2017-0228

7.5HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 May 2017

Summary

A remote code execution vulnerability exists in Microsoft browsers due to improper handling of objects in memory by JavaScript engines. This flaw allows attackers to gain control over affected systems, leading to potential unauthorized actions and data breaches. It is essential for users to ensure their browsers are updated to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft browsers Windows 8.1 for 32-bit systems, Windows 8.1 for x64-based systems, Windows RT 8.1, Windows Server 2012 R2, Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems, Windows 10 Version 1511 for 32-bit Systems, Windows 10 Version 1511 for x64-based Systems, Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows 10 Version 1703 for 32-bit Systems, Windows 10 Version 1703 for x64-based Systems, and Windows Server 2016.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.