CVE-2017-0064

medium
Published 2017-05-12 · Modified 2026-05-13
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
VIR risk
6.5

Description

A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability."

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftMicrosoft Forefront Security for SharePoint Service Pack 3
microsoftMicrosoft Security Essentials
microsoftMicrosoft Office for Mac 2011
microsoftMicrosoft PowerPoint for Mac 2011
microsoftWindows 7 for 32-bit Systems Service Pack 1
microsoftWindows 7 for x64-based Systems Service Pack 1
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
microsoftWindows Server 2008 R2 for Itanium-Based Systems Service Pack 1
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftMicrosoft Office 2007 Service Pack 3
microsoftMicrosoft Word 2007 Service Pack 3
microsoftWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
microsoftMicrosoft Forefront Endpoint Protection
microsoftWindows Intune Endpoint Protection
microsoftInternet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
microsoftInternet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftAdobe Flash Player on Windows Server 2012
microsoftAdobe Flash Player on Windows 8.1 for 32-bit systems
microsoftAdobe Flash Player on Windows 8.1 for x64-based systems
microsoftAdobe Flash Player on Windows Server 2012 R2
microsoftAdobe Flash Player on Windows RT 8.1
microsoftAdobe Flash Player on Windows 10 for 32-bit Systems
microsoftAdobe Flash Player on Windows 10 for x64-based Systems
microsoftAdobe Flash Player on Windows 10 Version 1511 for x64-based Systems
microsoftAdobe Flash Player on Windows 10 Version 1511 for 32-bit Systems
microsoftAdobe Flash Player on Windows Server 2016
microsoftAdobe Flash Player on Windows 10 Version 1607 for 32-bit Systems
microsoftAdobe Flash Player on Windows 10 Version 1607 for x64-based Systems

Application impact

VendorProductVersionsFixed
windows microsoftinternet_explorer9
windows microsoftinternet_explorer10
windows microsoftinternet_explorer11

References

💬 Discuss CVE-2017-0064 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.