CVE-2017-0055
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows
Microsoft Internet Information Server (IIS) in Windows Vista SP2.
Windows Server 2008 SP2 and R2.
Windows 7 SP1.
Windows 8.1.
Windows Server 2012 Gold and R2.
Windows RT 8.1.
Windows 10 Gold, 1511, and 1607.
and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability.".
MEDIUM · CVSS 6.1
EPSS 0.01387
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0