CVE-2017-0037

Scores

EPSS

0.905high90.5%
0%20%40%60%80%100%

Percentile: 90.5%

CVSS

8.1high3.x
0246810

CVSS Score: 8.1/10

All CVSS Scores

CVSS 3.x
8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Description

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

msrcnvd

CWEs

CWE-843

Related Vulnerabilities

Exploits

Exploit ID: CVE-2017-0037

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploit ID: 41454

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41454

Exploit ID: 42354

Source: exploitdb

URL: https://www.exploit-db.com/exploits/42354

Exploit ID: 43125

Source: exploitdb

URL: https://www.exploit-db.com/exploits/43125

Vulnerable Software (95)

Type: Configuration

Vendor: *

Product: edge

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"    }, ...

Source: nvd

Type: Configuration

Vendor: *

Product: internet_explorer

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 14393.953

Operating System: Windows 14393 build 953

Identifier: KB4013429

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10240.17319

Operating System: Windows 10240 build 17319

Identifier: KB4012606

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10586.839

Operating System: Windows 10586 build 839

Identifier: KB4013198

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4012216

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4015550

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4012204

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4056568

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4018271

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.000

Operating System: Windows 1 build 0

Identifier: KB5055515

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.007

Operating System: Windows 1 build 7

Identifier: KB5049994

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4103768

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.001

Operating System: Windows 1 build 1

Identifier: KB5043049

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4586768

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.001

Operating System: Windows 1 build 1

Identifier: KB5030209

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.000

Operating System: Windows 1 build 0

Identifier: KB5053593

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4343205

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4511872

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 6.0

Operating System: Windows 6 build 0

Identifier: KB5003165

Source: msrc