CVE-2017-0040Improper Restriction of Operations within the Bounds of a Memory Buffer in Corporation Internet Explorer

Severity
7.5HIGHNVD
EPSS
18.7%
top 4.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0130.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft_corporation/internet_explorerThe scripting engine in Microsoft Internet Explorer 9 through 11

Patches

🔴Vulnerability Details

4
GHSA
GHSA-ppg2-45gh-f84g: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memor2022-05-17
GHSA
GHSA-49xr-73x3-2444: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memor2022-05-17
CVEList
CVE-2017-0130: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memor2017-03-17
CVEList
CVE-2017-0040: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memor2017-03-17

📋Vendor Advisories

1
Microsoft
Scripting Engine Memory Corruption Vulnerability2017-03-14

🕵️Threat Intelligence

7
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins2017-03-15
CVE-2017-0040 — HIGH severity | cvebase