Vulnerability record · CVE-2017-0059 · published 17 March 2017
CVE-2017-0059: Internet Explorer memory information disclosure via crafted web site
Microsoft · Internet Explorer
Microsoft Internet Explorer 9 through 11 fails to properly handle objects in memory, allowing a crafted web site to read sensitive data from process memory. The flaw is distinct from CVE-2017-0008 and CVE-2017-0009 and was addressed by Microsoft in March 2017. Because the leaked memory can contain pointers or other sensitive data, it matters as a building block for further exploitation.
Description
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with public exploits and very high EPSS, but requires user interaction and only yields low confidentiality impact.
What it is
Microsoft Internet Explorer 9 through 11 fails to properly handle objects in memory, allowing a crafted web site to read sensitive data from process memory. The flaw is distinct from CVE-2017-0008 and CVE-2017-0009 and was addressed by Microsoft in March 2017. Because the leaked memory can contain pointers or other sensitive data, it matters as a building block for further exploitation.
Impact
An attacker who convinces a user to visit a malicious page can read contents of the browser process memory, potentially exposing sensitive information. The CVSS vector rates confidentiality impact as low, with no integrity or availability impact.
Attack surface
Reached over the network through a crafted web site rendered by Internet Explorer 9, 10 or 11; no authentication is required, but user interaction (visiting the page) is required per the CVSS vector UI:R.
Exploitation
CVE-2017-0059 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28) and has public Exploit-DB entries, and EPSS reports a 30-day exploitation probability of about 0.62 (99th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for CVE-2017-0059.
- Retire or migrate off Internet Explorer 9, 10 and 11 to a supported browser.
- Enforce a modern browser as the default and block IE rendering of untrusted sites where feasible.
- Restrict or monitor outbound browsing from high-value systems to reduce exposure to malicious pages.
Detection
- Hunt for Internet Explorer processes (iexplore.exe) loading pages from untrusted or newly registered domains.
- Monitor for crashes or abnormal memory-read behavior in iexplore.exe that may indicate exploitation attempts.
- Alert on known Exploit-DB payload patterns or exploit kit traffic associated with this CVE reaching endpoints.
- Track unpatched IE installations via vulnerability management and flag hosts still running IE 9-11.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0059 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Internet Explorer Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0059 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0059), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.