First published: Tue Dec 12 2017(Updated: )
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handle objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11906 and CVE-2017-11919.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =11 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Internet Explorer | =9 | |
Microsoft Windows Server 2008 Itanium | =sp2 | |
Internet Explorer | =10 | |
Microsoft Windows Server 2012 x64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11887 has a high severity rating due to its potential to allow attackers to gain sensitive information and compromise users' systems.
To fix CVE-2017-11887, install the latest security updates provided by Microsoft for affected versions of Internet Explorer and Windows.
CVE-2017-11887 affects Microsoft Internet Explorer versions 9, 10, and 11, and various versions of Windows including 7 SP1, 8.1, 10, and Windows Server editions.
Yes, CVE-2017-11887 can potentially be exploited remotely by an attacker to obtain sensitive information.
Exploitation of CVE-2017-11887 could lead to unauthorized access to sensitive data, further compromising the security of the affected system.