CVE-2018-0942
low-risk
Published 2018-03-14
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow elevation of privilege, due to how Internet Explorer handles zone and integrity settings, aka "Internet Explorer Elevation of Privilege Vulnerability".
Do I need to act?
~
1.9% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.6/10
Low
NETWORK
/ HIGH complexity
Affected Products (1)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/103312
Third Party Advisory
http://www.securitytracker.com/id/1040510
Third Party Advisory
http://www.securityfocus.com/bid/103312
Third Party Advisory
http://www.securitytracker.com/id/1040510
20
/ 100
low-risk
Severity
10/34 · Low
Exploitability
5/34 · Minimal
Exposure
5/34 · Minimal