CVE-2017-0210
Description
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
In plain language
AI Act nowCVE-2017-0210 is a Microsoft Internet Explorer weakness where a malicious website can take advantage of broken cross-site rules to steal or inject data; small businesses should treat it as high risk and update when available.
CVE-2017-0210 is an Internet Explorer cross-domain policy enforcement flaw that lets a malicious website use crafted browsing interactions to bypass browser isolation, enabling information access from one domain and injection into another without needing prior authentication.
What to do now
- Check whether your business uses Microsoft Internet Explorer and whether it is installed on any workstations.
- Update Internet Explorer (and any systems where it’s used) by applying Microsoft’s security updates for CVE-2017-0210.
- If you cannot update immediately, restrict Internet Explorer use by blocking it for users and routing employees to a supported browser until updates are applied.
- Verify after updating that the affected machines successfully received the Microsoft guidance updates associated with CVE-2017-0210.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-0210 and every CVE in our database. Create a free account — no credit card required.
Create Free Account