CVE-2017-11806 is a memory corruption vulnerability in ChakraCore and Microsoft Edge on Windows 10 version 1703, allowing an attacker to execute arbitrary code in the context of the current user. With a CVSS score of 7.5 (High), this vulnerability requires user interaction (UI:R) and has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Despite its high severity and significant community discussion, there is no public exploit code available in Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog. This vulnerability was addressed as part of Microsoft's October Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.