VulnerabilityModified
CVE-2017-0196
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
MEDIUM 6.5EPSS 18.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 18.15% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/edge
- Source
- secure@microsoft.com
References
- https://github.com/Microsoft/ChakraCore/commit/065b7978c40ded35c356ced6cd922a40156c9c46Issue Tracking, Patch, Third Party Advisory
- https://github.com/Microsoft/ChakraCore/commit/065b7978c40ded35c356ced6cd922a40156c9c46Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.