← back
CVE-2017-11855

CVE-2017-11855

EPSS 47.9%
Vexday Risk Score
35Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 47.9%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
15 Nov 2017Published on NVD
19 Dec 2017Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11856.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →