CVE-2017-11792 is a scripting engine memory corruption vulnerability affecting ChakraCore and Microsoft Edge on Windows 10 1703, allowing arbitrary code execution in the context of the current user. It carries a high CVSS score of 7.5, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. While not listed in CISA's KEV catalog, its EPSS score is notably high, suggesting a significant probability of exploitation. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, but it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.