Scripting Engine Memory Corruption in Microsoft Browsers on Windows Platforms
CVE-2017-8607
7.5HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 11 July 2017
Summary
This vulnerability allows an attacker to execute arbitrary code in the context of the current user due to a failure in the JavaScript engines of Microsoft browsers when handling objects in memory. The flaw impacts various versions of Windows, presenting significant security risks as it can be exploited to gain unauthorized access and control over affected systems.
Affected Version(s)
Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Microsoft browsers
References
EPSS Score
47% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved