An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97512 | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/97512 | Broken Link Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038238 | Broken Link Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038238 | Broken Link Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210 | Patch Vendor Advisory |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
10 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securitytracker.com/id/1038238 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/97512 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210 - Patch, Vendor Advisory |
02 Jul 2024, 13:01
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
|
References | (BID) http://www.securityfocus.com/bid/97512 - Broken Link, Third Party Advisory, VDB Entry | |
References | (SECTRACK) http://www.securitytracker.com/id/1038238 - Broken Link, Third Party Advisory, VDB Entry | |
First Time |
Microsoft windows 7
Microsoft windows 10 1703 Microsoft windows 10 1507 Microsoft windows 8.1 Microsoft windows 10 1511 Microsoft windows Server 2012 Microsoft windows Server 2016 Microsoft windows Rt 8.1 Microsoft windows Server 2008 Microsoft windows 10 1607 |
|
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 8.8 |
Information
Published : 2017-04-12 14:59
Updated : 2025-02-11 17:00
NVD link : CVE-2017-0210
Mitre link : CVE-2017-0210
JSON object : View
Products Affected
microsoft
- windows_7
- windows_8.1
- windows_10_1607
- windows_10_1703
- internet_explorer
- windows_10_1511
- windows_server_2012
- windows_rt_8.1
- windows_server_2016
- windows_10_1507
- windows_server_2008
CWE