cbcvebase.
CVE-2017-0149
published 2017-03-17

CVE-2017-0149: Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web…

PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-14
Exploited in the wild
EPSS
29.19%
97.9th percentile
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.

Affected

23 ranges
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoft_corporationinternet_explorer
msrcinternet_explorer_10_on_windows_server_2012
msrcinternet_explorer_11_on_windows_10_for_32-bit_systems
msrcinternet_explorer_11_on_windows_10_for_x64-based_systems
msrcinternet_explorer_11_on_windows_10_version_1511_for_32-bit_systems
msrcinternet_explorer_11_on_windows_10_version_1511_for_x64-based_systems
msrcinternet_explorer_11_on_windows_10_version_1607_for_32-bit_systems
msrcinternet_explorer_11_on_windows_10_version_1607_for_x64-based_systems
msrcinternet_explorer_11_on_windows_7_for_32-bit_systems_service_pack_1
msrcinternet_explorer_11_on_windows_7_for_x64-based_systems_service_pack_1
msrcinternet_explorer_11_on_windows_8.1_for_32-bit_systems
msrcinternet_explorer_11_on_windows_8.1_for_x64-based_systems
msrcinternet_explorer_11_on_windows_rt_8.1
msrcinternet_explorer_11_on_windows_server_2008_r2_for_x64-based_systems_service_pac
msrcinternet_explorer_11_on_windows_server_2012_r2
msrcinternet_explorer_11_on_windows_server_2016
msrcinternet_explorer_9_on_windows_server_2008_for_32-bit_systems_service_pack_2
msrcinternet_explorer_9_on_windows_server_2008_for_x64-based_systems_service_pack_2
msrcinternet_explorer_9_on_windows_vista_service_pack_2
msrcinternet_explorer_9_on_windows_vista_x64_edition_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

snort
Snort SIDs: 41549-41556, 41561-41598, 41601-41602, 41605-41610, 41633-41634, 41763-41764, 41926-41961, 41964-41998
  • CVE-2017-0149 is actively being exploited in the wild as of March 2017 Patch Tuesday; prioritize detection on Internet Explorer 9–11 memory corruption via crafted web content.
  • Exploitation confirmed on both latest and older software releases; treat any unpatched IE 9–11 instance as high-risk.
  • Attack vector is a specially crafted website or compromised/ad-hosting site; monitor for IE processes spawning unexpected child processes or network connections following web browsing.
  • Initial delivery commonly via email/IM lure or malicious attachment directing victim to attacker-controlled web content; correlate phishing emails with subsequent IE web requests.
  • ·Talos Snort SID ranges cover the full March 2017 Patch Tuesday bulletin set (MS17-006 through MS17-023), not exclusively CVE-2017-0149; verify which specific SIDs map to MS17-006/CVE-2017-0149 before deploying as targeted rules.
  • ·Additional Snort rules may be released after initial publication; consult Snort.org or your Management Center for the most current rule set.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.