Get real-time updates on Telegram
CVE-2017-8529: internet explorer 11, 9, 10; +2 more affected products
CVE-2017-8529. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.14203 (percentile 0.96504), scored 2026-10-08.
Affected technology
internet explorer · 11
microsoft
edge · Version not applicable in the source CPE
microsoft
internet explorer · 9
microsoft
internet explorer · 10
microsoft
Internet Explorer · Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016.
Microsoft Corporation
Description’s affected range: 8.1 and Windows RT 8.1, and Windows Server 2012 and R2
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
An attacker can detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability". NVD’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality impact as high; integrity and availability impact as none.
- CWE
- CWE-119
- CCR priority
- 29.6 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N · NVD
- EPSS
- 0.14203 · percentile 0.96504 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2017-8529.html