LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0059: Microsoft Internet Explorer Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0059 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

CVE-2017-0059 is an information disclosure vulnerability in Microsoft Internet Explorer. A remote attacker can use a crafted website to obtain sensitive information from the browser’s process memory. For IT and security teams, this matters because memory contents can include credentials, tokens, or other data the browser is handling, and exposure can aid further compromise even when full code execution is not involved.

CISA summarizes the issue as allowing remote attackers to obtain sensitive information from process memory via a crafted web site. The required action is to apply updates per vendor instructions. Confirm exact product scope and fixed builds against the Microsoft advisory before treating any host as clear.

How it works

This flaw is classed as CWE-200: exposure of sensitive information to an unauthorized actor. In Internet Explorer, the weakness lets a malicious page cause the browser to reveal data that should stay inside the process address space. An attacker typically lures a user to open or render attacker-controlled content in IE; once the page runs in the browser context, the vulnerability can leak memory contents back to the attacker.

Public detail in the provided record does not describe low-level exploit mechanics, heap layout, or specific APIs. Treat the abuse path as “user visits crafted site → IE discloses process memory.” Do not assume privilege escalation or ransomware delivery from this CVE alone; known ransomware use is not documented for this identifier. Always validate technical depth against the vendor advisory.

Am I affected? How to find it in your systems

Internet Explorer historically shipped with Windows client and server SKUs and may still appear where legacy web apps, kiosks, or enterprise line-of-business sites require it. Inventory every Windows endpoint and server that still has IE enabled or set as a default/secondary browser, including VDI images, jump hosts, and older application servers.

If inventory cannot prove a host is outside the advisory’s affected set, assume it needs the vendor update until verified.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2017-0059 exactly as named in the vendor advisory, following your standard test-and-deploy ring process. CISA’s required action is to apply updates per vendor instructions; do not substitute third-party “unofficial” fixes.

If you can't patch immediately

Until the vendor update is installed everywhere, shrink the window an attacker has to reach vulnerable IE instances.

Revisit compensating controls as soon as the official update can be deployed.

If your data may have been exposed

Actively exploited browser information-disclosure flaws can feed credential theft and follow-on intrusion even when ransomware use is not documented for this CVE. If IE users may have visited untrusted sites before patching, treat possible memory disclosure as a reason to rotate credentials that could have been in browser memory, review access logs for anomalous use of those identities, and continue incident triage per your playbooks. You can run a free exposure scan of your email addresses against known breach data to see whether those identities already appear in public breach corpora and prioritize further monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer
WeaknessCWE-200
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities