CVE-2017-11918 is a critical memory corruption vulnerability in ChakraCore and Microsoft Edge, affecting Windows 10 and Windows Server 2016. This flaw, rated High severity (CVSS 7.5), allows an unauthenticated attacker to execute arbitrary code with the same privileges as the logged-in user, typically requiring user interaction. While not currently listed in CISA's KEV catalog, public exploit code exists, and the vulnerability has received significant community discussion and media coverage, indicating a notable risk. Its high FAUCET Risk Score of 99/100 and high EPSS score further underscore the potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
< 1.7.5CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.