CVE Tools

Description

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."

In plain language

AI Act now

CVE-2017-0210 is a Microsoft Internet Explorer weakness where a malicious website can take advantage of broken cross-site rules to steal or inject data; small businesses should treat it as high risk and update when available.

Executive summary

CVE-2017-0210 is an Internet Explorer cross-domain policy enforcement flaw that lets a malicious website use crafted browsing interactions to bypass browser isolation, enabling information access from one domain and injection into another without needing prior authentication.

If affected, business impact
Steal sensitive business/customer dataManipulate web content in user sessionsAccount/session actions via tampered pagesOperational disruption from compromise

What to do now

  1. Check whether your business uses Microsoft Internet Explorer and whether it is installed on any workstations.
  2. Update Internet Explorer (and any systems where it’s used) by applying Microsoft’s security updates for CVE-2017-0210.
  3. If you cannot update immediately, restrict Internet Explorer use by blocking it for users and routing employees to a supported browser until updates are applied.
  4. Verify after updating that the affected machines successfully received the Microsoft guidance updates associated with CVE-2017-0210.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Microsoft Corp
commercial·USaka microsoft, microsoft corporation
Microsoft Corporation
commercial·USaka microsoft
and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 24, 2022
Remediation due:Jun 14, 2022

Required action: Apply updates per vendor instructions.

Official Patch Available

References

and 2 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-0210 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows