CVE-2017-11840 is a critical scripting engine memory corruption vulnerability affecting ChakraCore and Microsoft Edge on various Windows 10 and Server versions. An attacker can exploit this flaw to gain the same user rights as the current user. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this vulnerability requires user interaction (e.g., clicking a malicious link) but can lead to full compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploit code exists (EDB-43183), and it received significant community and media attention at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.