CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2017-8529: internet explorer 11, 9, 10; +2 more affected products

CVE-2017-8529. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.14203 (percentile 0.96504), scored 2026-10-08.

Affected technology

internet explorer · 11
microsoft

edge · Version not applicable in the source CPE
microsoft

internet explorer · 9
microsoft

internet explorer · 10
microsoft

Internet Explorer · Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016.
Microsoft Corporation

Description’s affected range: 8.1 and Windows RT 8.1, and Windows Server 2012 and R2

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

An attacker can detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability". NVD’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-119
CCR priority
29.6 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N · NVD
EPSS
0.14203 · percentile 0.96504 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2017-8529.html