CVE-2017-11796 is a memory corruption vulnerability in ChakraCore and Microsoft Edge on Windows 10 1703, allowing remote code execution in the context of the current user. With a CVSS score of 7.5 (High), successful exploitation requires user interaction and has high impacts on confidentiality, integrity, and availability. While no public exploit code is available and it's not in CISA's KEV catalog, its EPSS and FAUCET Risk Score indicate a notable potential for exploitation. Community discussion and media coverage are present, suggesting awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.