Memory Corruption Vulnerability in Microsoft Edge for Windows 10 and Server 2016
CVE-2017-8639

7.5HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 August 2017

Summary

The issue in Microsoft Edge arises from improper handling of memory objects by the browser's JavaScript engines. An attacker could exploit this vulnerability to execute arbitrary code within the context of the current user. Such an exploit could allow unauthorized actions on the system if the user has sufficient privileges. Users are encouraged to update their systems to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Microsoft Scripting Engine Windows 10 1607, 1703, and Windows Server 2016.

References

EPSS Score

34% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.