CVE-2017-0137 is a remote code execution vulnerability affecting Microsoft Edge, Windows 10, and Windows Server 2016. It stems from how Microsoft scripting engines handle objects in memory, potentially leading to memory corruption. With a CVSS score of 7.5 (High), an attacker could exploit this vulnerability remotely with high attack complexity, gaining the same user rights as the current user, including administrative control. While the EPSS score indicates a higher than average exploitability probability, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.