Vulnerability record · CVE-2017-11890 · published 12 December 2017
CVE-2017-11890: Internet Explorer Scripting Engine Memory Corruption RCE
Microsoft · Internet Explorer
Internet Explorer mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Microsoft addressed it in the December 2017 updates across Windows 7 through Windows 10 and corresponding server releases. Because IE is still present on many of these platforms, unpatched hosts remain exposed to code execution in the user's context.
Description
Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityPublic exploit code and a very high EPSS score make this attractive to attackers, though the high attack complexity and required user interaction temper the risk.
What it is
Internet Explorer mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Microsoft addressed it in the December 2017 updates across Windows 7 through Windows 10 and corresponding server releases. Because IE is still present on many of these platforms, unpatched hosts remain exposed to code execution in the user's context.
Impact
An attacker can execute arbitrary code with the privileges of the current user. That typically means full control of the browsing session and any data or credentials the user can reach, with further host compromise possible if the user has elevated rights.
Attack surface
Reached over the network (AV:N) through IE rendering of attacker-controlled content, with user interaction required (UI:R) and no authentication needed (PR:N). The high attack complexity (AC:H) indicates the memory corruption is not trivially reliable.
Exploitation
A public exploit exists (Exploit-DB 43369), and EPSS is high at roughly 0.50 (98.8th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the Microsoft December 2017 security updates for all affected Windows versions, prioritizing Windows 7 SP1, Server 2008/R2, 8.1/RT 8.1, Server 2012/R2, Windows 10 builds through 1709, and Server 2016.
- Retire or disable Internet Explorer where possible and standardize users on a supported browser.
- Enforce Enhanced Protected Mode / 64-bit IE and other IE hardening where IE must remain.
- Block or restrict untrusted web content at the network and email gateway, and limit users' ability to browse arbitrary sites.
- Run users without local administrator rights to reduce the value of code execution in the user context.
Detection
- Hunt for IE (iexplore.exe) spawning child processes such as cmd.exe, powershell.exe, wscript.exe or rundll32.exe.
- Monitor for crashes or memory-corruption indicators in iexplore.exe and for unusual outbound connections from IE processes.
- Alert on known exploit artifacts tied to Exploit-DB 43369 and on hosts still missing the December 2017 cumulative updates.
- Review proxy and DNS logs for users reaching pages that deliver IE-targeted exploit kits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102082 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039991 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11890 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43369/ | ExploitIssue TrackingThird Party Advisory |
| http://www.securityfocus.com/bid/102082 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039991 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11890 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43369/ | ExploitIssue TrackingThird Party Advisory |
Track CVE-2017-11890 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11890), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.