CVE-2017-11856

Description

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka Internet Explorer Memory Corruption Vulnerability. This CVE ID is unique from CVE-2017-11855.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
20.786

Associated Vulnerability

VulnerabilityOS Platform
Scripting Engine Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4048957)Windows
Scripting Engine Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4048957)Windows
Scripting Engine Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4048957)Windows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB4048952) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1511 for x86-based Systems (KB4048952) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4048953) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4048953) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4048953) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4048953) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4048953) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4048953) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4048956) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4048954) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4048954) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4048954) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4048954) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4048955) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4048955) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4048955) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4048955) - DeltaWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 10 for Windows Server 2012 (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 11 for Windows 8.1 for x64-based Systems and Windows Server 2012 R2 (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 11 for Windows 8.1 (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 11 for Windows 7 for x64-based Systems and Windows Server 2008 R2(KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 11 for Windows 7 (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Internet Explorer 9 for Windows Server 2008 (KB4047206) - CumulativeWindows
Scripting Engine Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4048958)Windows
Scripting Engine Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4048958)Windows
Scripting Engine Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4048958)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-233742017-11 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4048957)
PATCH-233732017-11 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4048957)
PATCH-233722017-11 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4048957)
PATCH-23436Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB4048952)
PATCH-23435Cumulative Update for Windows 10 Version 1511 for x86-based Systems (KB4048952)
PATCH-23438Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4048953)
PATCH-23437Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4048953)
PATCH-23439Cumulative Update for Windows Server 2016 for x64-based Systems (KB4048953)
PATCH-23442Delta Update for Windows Server 2016 for x64-based Systems (KB4048953)
PATCH-23441Delta Update for Windows 10 Version 1607 for x64-based Systems (KB4048953)
PATCH-23440Delta Update for Windows 10 Version 1607 for x86-based Systems (KB4048953)
PATCH-23434Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4048956)
PATCH-23448Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4048955)
PATCH-23483Delta Update for Windows 10 Version 1709 for x64-based Systems (KB4048955)
PATCH-23447Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4048955)
PATCH-23482Delta Update for Windows 10 Version 1709 for x86-based Systems (KB4048955)
PATCH-23395Cumulative Security Update for Internet Explorer 10 for Windows Server 2012 (KB4047206)
PATCH-23396Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB4047206)
PATCH-23393Cumulative Security Update for Internet Explorer 11 for Windows 7 (KB4047206)
PATCH-23392Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4047206)
PATCH-23391Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 (KB4047206)
PATCH-233772017-11 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4048958)
PATCH-233762017-11 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4048958)
PATCH-233752017-11 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4048958)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234