Vulnerability record · CVE-2017-11907 · published 12 December 2017
CVE-2017-11907: Internet Explorer scripting engine memory corruption
Microsoft · Internet Explorer
Internet Explorer mishandles objects in memory, producing a memory corruption condition (CWE-119) in the scripting engine. A remote attacker can trigger it to run code with the rights of the current user, which matters because IE shipped by default across a wide range of Windows versions listed in the advisory.
Description
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with public exploit code and very high EPSS, though exploitation requires user interaction and the affected browser is legacy.
What it is
Internet Explorer mishandles objects in memory, producing a memory corruption condition (CWE-119) in the scripting engine. A remote attacker can trigger it to run code with the rights of the current user, which matters because IE shipped by default across a wide range of Windows versions listed in the advisory.
Impact
Successful exploitation gives the attacker the same privileges as the logged-on user, enabling code execution in the browser's context. Because the flaw is memory corruption, a failed attempt can also crash the browser.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically the victim visiting a crafted page or opening attacker-supplied content in Internet Explorer. No authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64733 (99.2nd percentile) and a public Exploit-DB entry (43370) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11907.
- Retire or disable Internet Explorer where possible and standardize on a supported browser.
- Enforce Protected Mode and other IE security zones, and block untrusted ActiveX and scripting content.
- Restrict users from browsing untrusted sites and opening unsolicited links or attachments.
- Where IE cannot be removed, keep the OS fully patched and monitor for IE crashes as a possible exploitation signal.
Detection
- Monitor for iexplore.exe crashes and unexpected child processes spawned by Internet Explorer.
- Alert on IE making outbound connections or loading content from newly seen or low-reputation domains.
- Hunt for known Exploit-DB 43370 artifacts and related scripting-engine exploit patterns in proxy and endpoint logs.
- Review endpoint telemetry for process creation where iexplore.exe is the parent of scripting or command interpreters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102045 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039991 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11907 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43370/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102045 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039991 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11907 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43370/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11907), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.