CVE-2017-11819 is a remote code execution vulnerability affecting Microsoft Windows 7 SP1, stemming from how Microsoft browsers handle objects in memory. This high-severity flaw, with a CVSS score of 7.5, allows an attacker to execute arbitrary code in the context of the current user, requiring user interaction and a high attack complexity. Despite its age, the vulnerability has a high FAUCET Risk Score of 91/100 and an EPSS score indicating a higher-than-average likelihood of exploitation. While not listed in CISA's KEV catalog and lacking public exploit intelligence in Metasploit, Nuclei, or ExploitDB, it did receive media coverage during its disclosure, suggesting some awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.