CVE-2017-11801 is a scripting engine information disclosure vulnerability in Microsoft ChakraCore that allows an attacker to execute arbitrary code in the context of the current user. It carries a high CVSS score of 7.5, indicating a significant risk due to its network-based attack vector, high impact on confidentiality, integrity, and availability, despite requiring user interaction and having high attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community. This CVE was addressed as part of Microsoft's October Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.