CVE-2017-0154: Microsoft Internet Explorer

Medium severity, CVSS 4.4. EPSS: 10.6% chance of exploitation in the next 30 days.

Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."

Affected products

Published 2017-03-17. Last modified 2026-06-17.