cbcvebase.
CVE-2017-11869
published 2017-11-15

CVE-2017-11869: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold…

PriorityP274high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
9.83%
95.0th percentile
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftinternet_explorer
msrcinternet_explorer_10
msrcinternet_explorer_11
msrcinternet_explorer_9

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in Internet Explorer's scripting engine (Microsoft Scripting Engine) handling of objects in memory — monitor for IE process spawning unexpected child processes or executing arbitrary code in user context
  • Attack vector is drive-by via specially crafted website or compromised/ad-hosting sites viewed in Internet Explorer — monitor for IE navigating to unusual or newly-registered domains, especially via email/IM lure links
  • Exploitation likelihood is rated 'More Likely' for both latest and older software releases — prioritize detection and patching for all IE-enabled systems
  • ·CVE-2017-11869 affects Internet Explorer via the Microsoft Scripting Engine, not ChakraCore/Edge — Doc 1 describes a different CVE (CVE-2017-11840); do not conflate the two vulnerabilities
  • ·As of advisory publication, the vulnerability had NOT been publicly exploited or disclosed in the wild — no active exploit IOCs were available at time of reporting

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.