Memory Corruption Vulnerability in Microsoft Browsers on Windows Platforms
CVE-2017-8608

7.5HIGH

Summary

This vulnerability exists in Microsoft browsers pertaining to various versions of Windows. It allows an attacker to execute arbitrary code within the context of the current user due to failures in the JavaScript engine when managing objects in memory. Attackers exploiting this vulnerability could gain the same user rights as the current user, potentially leading to unauthorized access and manipulation of the system. It highlights the need for continuous monitoring and timely updates to safeguard against such exploits.

Affected Version(s)

Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016. Microsoft browsers

References

EPSS Score

47% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.