CVE-2017-0070 is a remote code execution vulnerability affecting Microsoft Edge and Windows 10/Server 2016, stemming from how Microsoft scripting engines handle objects in memory, leading to memory corruption. This high-severity vulnerability (CVSS 7.5) has a network attack vector and requires user interaction, but successful exploitation could grant an attacker the same privileges as the current user, potentially leading to full system compromise. While not listed on the KEV catalog or Hot List, a public exploit (EDB-41623) exists for Microsoft Edge, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.