CVE-2017-0241 describes an elevation of privilege vulnerability in Microsoft Edge. This flaw allows Edge to render a domain-less page in the URL, enabling it to operate within the Intranet Zone context and access functionality typically restricted to the Internet Zone. With a CVSS score of 5.3 (Medium), exploitation requires user interaction and high attack complexity, potentially leading to high integrity impact but no confidentiality or availability impact. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), this vulnerability was reportedly exploited in the wild by Russian-linked cyberespionage groups, indicating active exploitation despite its inactive status on the CISA KEV catalog. Community discussion and media coverage suggest significant attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.