Scripting Engine Memory Corruption in Microsoft Edge Affects Windows 10 and Server
CVE-2017-8657

7.5HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 August 2017

Summary

An issue in Microsoft Edge's JavaScript engines allows attackers to manipulate memory objects, resulting in the potential execution of arbitrary code within the context of a vulnerable user's session. This vulnerability arises from improper rendering of certain content types, potentially allowing threat actors to exploit the flaw for malicious purposes. Affected systems include various versions of Windows 10 and Windows Server 2016, emphasizing the importance of timely security updates and adherence to best practices in device security.

Affected Version(s)

Microsoft Scripting Engine Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016.

References

EPSS Score

64% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.