Vulnerability record · CVE-2017-0149 · published 17 March 2017
CVE-2017-0149: Internet Explorer memory corruption out-of-bounds write
Microsoft · Internet Explorer
Microsoft Internet Explorer 9 through 11 contains an out-of-bounds write (CWE-787) that corrupts memory when a crafted web page is rendered. A remote attacker can exploit it to run arbitrary code in the context of the browser or crash it. The flaw is distinct from CVE-2017-0018 and CVE-2017-0037.
Description
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and CISA KEV listing indicate active exploitation, though user interaction and the legacy IE target reduce exposure.
What it is
Microsoft Internet Explorer 9 through 11 contains an out-of-bounds write (CWE-787) that corrupts memory when a crafted web page is rendered. A remote attacker can exploit it to run arbitrary code in the context of the browser or crash it. The flaw is distinct from CVE-2017-0018 and CVE-2017-0037.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the IE process, or a denial of service through memory corruption.
Attack surface
Reached over the network by luring a user to a crafted web site; no authentication is required but user interaction (visiting the page) is needed per the CVSS vector AV:N/UI:R.
Exploitation
CVE-2017-0149 is listed in CISA KEV (added 2022-05-24), indicating known exploitation, and EPSS shows a 30-day probability of 0.29178 (98th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com advisory CVE-2017-0149) to all affected IE 9-11 installations.
- Retire or migrate off Internet Explorer 9-11 where possible, since the product is no longer supported.
- Enforce a modern browser as default and block IE rendering of untrusted sites via enterprise mode or site lists.
- Restrict browsing to trusted sites and disable ActiveX/scripting where IE must remain in use.
Detection
- Monitor for IE process crashes (iexplore.exe) with memory corruption fault offsets and correlate with recent web browsing.
- Hunt for iexplore.exe spawning child processes such as cmd.exe, powershell.exe or script hosts, which indicates post-exploitation.
- Review proxy and DNS logs for access to known exploit-hosting or malvertising domains tied to IE exploits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0149 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Microsoft Internet Explorer Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96724 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038008 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0149 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/96724 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038008 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0149 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0149 | US Government Resource |
Track CVE-2017-0149 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0149), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.