CVE-2017-0222: Microsoft Internet Explorer Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-02-25. EPSS: 29.6% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

Affected products

  • Microsoft Internet Explorer: version 9 only; version 11 only

Published 2017-05-12. Last modified 2026-06-17.