CVE-2017-0154: Microsoft Internet Explorer
Medium severity, CVSS 4.4. EPSS: 10.6% chance of exploitation in the next 30 days.
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
Affected products
- Microsoft Internet Explorer: version 11 only
Published 2017-03-17. Last modified 2026-06-17.