CVE-2017-11874 describes a security feature bypass vulnerability in Microsoft Edge, ChakraCore, and Windows 10/Server. This flaw allows an attacker to bypass Control Flow Guard (CFG) due to how Edge's Just-In-Time (JIT) compiler handles memory access, potentially leading to arbitrary code execution. The vulnerability has a low CVSS score of 3.1, indicating a network-based attack requiring user interaction and high attack complexity, with a limited impact on integrity. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.