CVE-2017-11811 is a critical memory corruption vulnerability affecting ChakraCore and Microsoft Edge on various Windows 10 and Server 2016 versions. This flaw allows an attacker to execute arbitrary code in the context of the current user due to improper handling of objects in memory by the scripting engine. With a CVSS score of 7.5 (High), exploitation requires user interaction (e.g., visiting a malicious website) but can lead to full compromise of the user's system. While not listed in CISA KEV, public exploit code exists, and the vulnerability has garnered significant community discussion and media coverage, indicating its potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
< 1.7.3CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.