CVE-2017-0049: Microsoft Internet Explorer

Medium severity, CVSS 4.3. EPSS: 38.9% chance of exploitation in the next 30 days.

The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0018, and CVE-2017-0037.

Affected products

Published 2017-03-17. Last modified 2026-06-17.