Scripting Engine Memory Corruption Vulnerability in Microsoft Edge
CVE-2017-8645
7.5HIGH
Summary
The vulnerability in Microsoft Edge allows attackers to execute arbitrary code in the context of the current user due to improper handling of objects in memory by the browser's JavaScript engine. This exploitation can occur when the browser renders content, potentially leading to unauthorized actions or access. Users on specified Windows 10 and Windows Server 2016 versions are advised to update promptly to mitigate risks associated with this vulnerability.
Affected Version(s)
Microsoft Scripting Engine Windows 10 1511, 1607, 1703, and Windows Server 2016.
References
EPSS Score
64% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved