CVE-2017-11888 is a memory corruption vulnerability in Microsoft Edge affecting various versions of Windows 10 and Windows Server 2016. This flaw allows an unauthenticated attacker to execute arbitrary code in the context of the current user, typically through a crafted webpage. Rated with a CVSS score of 7.5 (High), exploitation requires user interaction and has high impacts on confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, indicating awareness. It is not currently listed in CISA's KEV catalog as being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.