---
id: CVE-2017-8529
title: >-
  Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1,
  Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an
  attacker to detect specific files on the user's computer when affected
  Microsoft scripting …
summary: >-
  Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1,
  Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an
  attacker to detect specific files on the user's computer when affected
  Microsoft scripting …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-119
vendor: microsoft
product: internet_explorer
affected:
  - internet_explorer = 11
  - edge
  - internet_explorer = 9
  - internet_explorer = 10
published: '2017-06-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:42.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-8529'
references:
  - url: 'http://www.securityfocus.com/bid/98953'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8529
    label: secure@microsoft.com
  - url: 'http://www.securityfocus.com/bid/98953'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8529
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.14203
epssPercentile: 0.96504
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/sfitpro/cve-2017-8529'
  checkedAt: '2026-10-08T23:17:21.727Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.284Z'
---

## Overview

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".

## Affected

- `internet_explorer = 11`
- `edge`
- `internet_explorer = 9`
- `internet_explorer = 10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
