CVE-2017-0210: Microsoft Internet Explorer Privilege Escalation Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-24. EPSS: 22.3% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."

Affected products

  • Microsoft Internet Explorer: version 10 only; version 11 only

Published 2017-04-12. Last modified 2026-06-17.