CVE-2017-0234 is a remote code execution vulnerability affecting Microsoft Edge, stemming from memory corruption within the Chakra JavaScript engine. An attacker could exploit this by crafting a malicious website that, when visited by a user, could lead to arbitrary code execution. This vulnerability carries a high CVSS score of 7.5, indicating a significant impact on confidentiality, integrity, and availability, with a network attack vector and high attack complexity requiring user interaction. While there is no evidence of active exploitation in the wild (KEV), its high EPSS score and FAUCET Risk Score suggest a notable potential for future exploitation, though no public exploit code or Metasploit modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.