| Vulnerability Name: | CVE-2017-8547 (CCN-126806) | ||||||||||||
| Assigned: | 2017-06-13 | ||||||||||||
| Published: | 2017-06-13 | ||||||||||||
| Updated: | 2017-06-26 | ||||||||||||
| Summary: | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8519. | ||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-119 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-8547 Source: BID Type: Third Party Advisory, VDB Entry 98932 Source: CCN Type: BID-98932 Microsoft Internet Explorer CVE-2017-8547 Remote Memory Corruption Vulnerability Source: XF Type: UNKNOWN ms-ie-cve20178547-code-exec(126806) Source: CCN Type: Microsoft Security TechCenter CVE-2017-8547 | Internet Explorer Memory Corruption Vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8547 Source: CCN Type: ZDI-17-401 Microsoft Internet Explorer InsertRow Out-Of-Bounds Read Remote Code Execution Vulnerability | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||