CVE-2017-11764 is a scripting engine memory corruption vulnerability in Microsoft Edge affecting Windows 10 (versions 1607, 1703) and Windows Server 2016, allowing arbitrary code execution in the context of the current user. It carries a high CVSS score of 7.5, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though requiring user interaction and having high attack complexity. While not listed in KEV or having Metasploit/Nuclei exploits, an ExploitDB entry exists for a related denial-of-service vulnerability, and it has received significant community and media attention. The vulnerability is currently inactive on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.