CVE-2017-11889 is a critical memory corruption vulnerability affecting ChakraCore and Microsoft Edge on various Windows 10 and Server 2016 versions. This flaw allows an unauthenticated attacker to execute arbitrary code in the context of the current user by exploiting how the scripting engine handles objects in memory. With a CVSS score of 7.5 (High), exploitation requires user interaction (e.g., visiting a malicious website) but can lead to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.5CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.