CVE-2017-0065

MEDIUM

Microsoft Edge - Information Disclosure via Crafted Web Site

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-0065. PoCs published by Dankirk.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2017-0065, which abuses Microsoft Edge's `read://` URL handler to exfiltrate local files without user consent. The exploit requires a forged HTML file placed in a specific directory and a malicious server to capture the leaked data.

Description

Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068.

Exploits (1)

nomisec WORKING POC 15 stars
by Dankirk · poc
https://github.com/Dankirk/cve-2017-0065

This repository contains a functional exploit for CVE-2017-0065, which abuses Microsoft Edge's `read://` URL handler to exfiltrate local files without user consent. The exploit requires a forged HTML file placed in a specific directory and a malicious server to capture the leaked data.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Edge (pre-MS17-007)
No auth needed
Prerequisites: Victim must have a forged `exploit.html` file in `c:\windows\System32\drivers\etc\` · Attacker must host `malicious_server.php` on a PHP-enabled web server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038006
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96648

Scores

CVSS v3 4.3
EPSS 0.2718
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
microsoft/edge
Microsoft Corporation/Edge Edge
Published Mar 17, 2017
Tracked Since Feb 18, 2026