CVE-2017-0154 is an Elevation of Privilege vulnerability affecting Microsoft Internet Explorer 11 on specific versions of Windows 10 and Windows Server 2016. This flaw allows attackers to bypass cross-domain policies, enabling them to access information from one domain and inject it into another through a specially crafted application. With a CVSS score of 4.4 (Medium), it requires user interaction (UI:R) and local access (AV:L), leading to potential low impact on confidentiality and integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.