Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-0059

85
FAUCET Score

CVE-2017-0059 is an information disclosure vulnerability affecting Microsoft Internet Explorer versions 9 through 11, allowing remote attackers to extract sensitive data from process memory via a crafted website. Rated as Medium severity (CVSS 4.3), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to a loss of confidentiality (C:L). This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and a high EPSS score, despite a lack of public Metasploit or Nuclei modules. While there are ExploitDB entries related to IE11 memory disclosure and RCE, direct exploit code for this specific information disclosure is not explicitly listed.

Impacted Technologies

VendorProductVersion(s)CPE
9CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
61.97%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 28, 2022
ExploitDB: EDB-43125 · Oct 17, 2017
This CVE's current EPSS score of 0.6197 is in the 100th percentile among its peer group of 26,234 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (39)

microsoftpatch availablevia msrc
Product: 10555-10378
View patch
microsoftpatch availablevia msrc
Product: 10486-10481
View patch
microsoftpatch availablevia msrc
Product: 10486-10482
View patch
microsoftpatch availablevia msrc
Product: 10486-10483
View patch
microsoftpatch availablevia msrc
Product: 10486-10047
View patch
microsoftpatch availablevia msrc
Product: 10486-10048
View patch
microsoftpatch availablevia msrc
Product: 10336-9316
View patch
microsoftpatch availablevia msrc
Product: 10336-4393
View patch
microsoftpatch availablevia msrc
Product: 10336-9312
View patch
microsoftpatch availablevia msrc
Product: 10336-9318
View patch
microsoftpatch availablevia msrc
Product: 10486-10484
microsoftpatch availablevia msrc
Product: 10486-10051
View patch
microsoftpatch availablevia msrc
Product: 10486-10729
View patch
microsoftpatch availablevia msrc
Product: 10486-10735
View patch
microsoftpatch availablevia msrc
Product: 10486-10789
View patch
microsoftpatch availablevia msrc
Product: 10486-10788
View patch
microsoftpatch availablevia msrc
Product: 10486-10852
View patch
microsoftpatch availablevia msrc
Product: 10486-10853
View patch
microsoftpatch availablevia msrc
Product: 10486-10816
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 10 on Windows Server 2012
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 9 on Windows Vista x64 Edition Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 9 on Windows Vista Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 8.1 for 32-bit systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 8.1 for x64-based systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows Server 2012 R2
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows RT 8.1
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 Version 1511 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 Version 1511 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Internet Explorer 11 on Windows Server 2016
View patch
microsoftpatch availablevia nvd_reference
View patch

Vendor Advisories (1)

microsoft2017-Mar/CVE-2017-0059Low

Microsoft Browser Information Disclosure Vulnerability

Mar 14, 2017

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
portal.msrc.microsoft.com / en-US/security-guidance/advisory/CVE-2017-0059
PatchVendor Advisory
exploit-db.com / exploits/41661
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/42354
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/43125
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/96645
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1038008
Broken LinkThird Party AdvisoryVDB Entry