First published: Tue Dec 12 2017(Updated: )
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =11 | |
Windows 10 | ||
Windows 10 | =1511 | |
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Internet Explorer | =10 | |
Microsoft Windows Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11901 is rated as important due to its potential to allow attackers to gain the same user rights as the current user.
To fix CVE-2017-11901, users should apply the latest security updates provided by Microsoft for the affected versions of Internet Explorer.
CVE-2017-11901 affects Internet Explorer version 11.
CVE-2017-11901 can primarily affect systems running outdated versions of Internet Explorer on Windows 7, Windows Server 2008 R2, Windows 8.1, and Windows 10.
No, CVE-2017-11901 specifically affects Internet Explorer and does not impact Microsoft Edge.