CVE-2017-11834
published 2017-11-15CVE-2017-11834: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10…
PriorityP432medium5.3CVSS 3.0
AVNACHPRNUIRSUCHINAN
EPSS
12.73%
95.8th percentile
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft_corporation | internet_explorer | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c9qm-8jwg-853p: ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-11791 [MEDIUM] CWE-200 GHSA-c9qm-8jwg-853p: ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11834.
GHSA
GHSA-pr55-xhmq-xc23: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17·CVSS 3.1
CVE-2017-11834 [LOW] CWE-200 GHSA-pr55-xhmq-xc23: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
Microsoft
Scripting Engine Information Disclosure Vulnerability
vendor_msrc·2017-11-14·CVSS 4.2
CVE-2017-11834 [MEDIUM] Scripting Engine Information Disclosure Vulnerability
Scripting Engine Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
In a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an att
No detection rules found.
No public exploits indexed.
Unit42
Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
blogs_unit42·2017-11-22·CVSS 3.1
CVE-2017-11855 [LOW] Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered four vulnerabilities addressed by the Microsoft Security Response Center as part of their November 2017 security update release.
CVE
Vulnerability Name
Affected Products
Maximum Severity Rating
Impact
Researcher(s)
CVE-2017-11855
Internet Explorer Memory Corruption Vulnerability
Internet Explorer 9, 10, 11
Critical
Remote Code Execution (RCE)
Hui Gao
CVE-2017-11856
Internet Explorer Memory Corruption Vulnerability
Internet Explorer 11
Critical
Remote Code Execution (RCE)
Hui Gao and Zhanglin He
CVE-2017-11791
Scripting Engine Information Disclosure Vulnerability
Internet Explorer 9, 10, 11; Microsoft Edge
Important
Information Disclosure
Hui Gao
CVE-2017-11834
Unit42
Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
blogs_unit42·2017-11-22·CVSS 3.1
[LOW] Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
## Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
Unit 42
Published: November 22, 2017
Threat Research
Vulnerabilities
Internet Explorer
Microsoft
Microsoft Security Response Center (MSRC)
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered four vulnerabilities addressed by the Microsoft Security Response Center as part of their November 2017 security update release.
CVE
Vulnerability Name
Affected Products
Maximum Severity Rating
Impact
Researcher(s)
CVE-2017-11855
Internet Explorer Memory Corruption Vulnerability
Internet Explorer 9, 10, 11
Critical
Remote Code Execution (RCE)
Hui Gao
CVE-2017-11856
Internet Explorer Memory Corruption Vulnerability
Internet Explo
Talos
Microsoft Patch Tuesday - November 2017
blogs_talos·2017-11-14·CVSS 7.5
CVE-2017-16367 [HIGH] Microsoft Patch Tuesday - November 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 53 new vulnerabilities with 19 of them rated critical, 31 of them rated important and 3 of them rated moderate. These vulnerabilities impact Microsoft Edge, Internet Explorer, Microsoft Scripting Engine, and more.
In addition, an update for Adobe Reader was released which addresses CVE-2017-16367 / TALOS-2017-0356 - Adobe Acrobat Reader DC PDF Structured Hierarchy ActualText Structure Element Code Execution Vulnerability which was discovered by Aleksandar Nikolic of Cisco Talos. This vulnerability manifests as a type confusion vulnerability in the PDF parsing functionality for documents containing marked stru
http://www.securityfocus.com/bid/101725http://www.securitytracker.com/id/1039796https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11834http://www.securityfocus.com/bid/101725http://www.securitytracker.com/id/1039796https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11834
2017-11-15
Published