CVE-2017-11797 is a high-severity information disclosure vulnerability in Microsoft ChakraCore, allowing arbitrary code execution in the context of the current user due to improper handling of objects in memory. With a CVSS score of 7.5, it requires user interaction and has high impacts on confidentiality, integrity, and availability. Despite its high FAUCET Risk Score of 91/100 and notable community discussion, there is no public exploit code available, and it is not listed on the CISA KEV catalog. This vulnerability was addressed as part of Microsoft's October Patch Tuesday, which included fixes for 62 security issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.