CVE-2017-11839 is a scripting engine memory corruption vulnerability in Microsoft Edge affecting Windows 10 and Windows Server 2016. This flaw allows an unauthenticated, remote attacker to gain full control of an affected system by exploiting how the scripting engine handles objects in memory. Rated with a CVSS score of 7.5 (High), this vulnerability requires user interaction (UI:R) but can be exploited over the network (AV:N) with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Its high EPSS score of 0.80398 indicates a significant probability of exploitation. While not currently listed on the CISA KEV catalog, an exploit (EDB-43180) exists on ExploitDB, demonstrating a Chakra JIT type confusion. The vulnerability has garnered community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.