CVE-2017-0149: Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
Other sources
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0149?
CVE-2017-0149 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2017-0149?
To remediate CVE-2017-0149, you should apply the security updates released by Microsoft for Internet Explorer 9, 10, and 11.
Which versions of Internet Explorer are affected by CVE-2017-0149?
CVE-2017-0149 affects Microsoft Internet Explorer versions 9, 10, and 11.
What type of attack does CVE-2017-0149 enable?
CVE-2017-0149 enables attackers to execute arbitrary code or cause a denial of service through memory corruption.
Is there a workaround for CVE-2017-0149?
There are no effective workarounds for CVE-2017-0149; the best mitigation is to update to the latest version of Internet Explorer.