8.8

CVE-2017-0210

Warnung
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 10 1607 Version -
   Microsoft ≫ Windows 10 1703 Version -
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
   Microsoft ≫ Windows Server 2012 Version r2
   Microsoft ≫ Windows Server 2016 Version -

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Internet Explorer Privilege Escalation Vulnerability

Schwachstelle

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.52% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securitytracker.com/id/1038238
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/97512
Third Party Advisory
Broken Link
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0210
US Government Resource