CVE-2017-11845 describes a memory corruption vulnerability in Microsoft Edge on Windows 10 1703, allowing an attacker to execute arbitrary code in the context of the current user. This is a high-severity vulnerability with a CVSS score of 7.5, requiring user interaction (UI:R) and high attack complexity (AC:H), but potentially leading to high impact on confidentiality, integrity, and availability. While the vulnerability has a high FAUCET Risk Score of 88/100 and notable media coverage, there is no evidence of active exploitation (KEV: No), nor are there public exploits available on platforms like Metasploit or ExploitDB. Community discussion is limited, with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.