Record summary

CVE-2017-0059 has a selected CVSS score of 4.3 (medium); EIP currently links 3 catalogued exploits. CISA lists CVE-2017-0059 in KEV.

Description

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 28, 2022 · CISA
VulnCheck KEV
Listed · Aug 30, 2017 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
3

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListInternet Explorer 9 through 11affected

Proofs of concept

3

Catalogued exploits

ExploitDBMicrosoft Internet Explorer 11 - 'textarea.defaultValue' Memory Disclosure (MS17-006)ExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details
ExploitDBMicrosoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)ExploitDB exploitby redr2eNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details
ExploitDBMicrosoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)ExploitDB exploitby mschenkNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

8