Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-5124

30
FAUCET Score

CVE-2017-5124 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome's Blink rendering engine prior to version 62.0.3202.62, specifically affecting how MHTML pages were handled. This flaw allowed a remote attacker to inject arbitrary scripts or HTML by crafting a malicious MHTML page, impacting Google Chrome and Debian Linux distributions. With a CVSS score of 6.1 (Medium), this vulnerability is exploitable over the network with low attack complexity, requiring user interaction. A successful exploit could lead to limited confidentiality and integrity impacts, allowing attackers to potentially steal sensitive information or deface websites. While not listed on CISA's KEV catalog, exploit code for this vulnerability (EDB-45867) is publicly available. The CVE has garnered significant community discussion and media coverage, indicating a high level of awareness despite its inactive status on the Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
< 62.0.3202.62CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.15%
Probability of exploitation in next 30 days
EPSS Percentile
91.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-45867 · Oct 3, 2017
This CVE's current EPSS score of 0.0515 is in the 96th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:62.0.3202.62-2.el6_9
View patch

Vendor Advisories (1)

redhatCVE-2017-5124Important

chromium-browser: uxss with mhtml

Oct 17, 2017

References

access.redhat.com / errata/RHSA-2017:2997
chromereleases.googleblog.com / 2017/10/stable-channel-update-for-desktop.html
chromium.googlesource.com / chromium/src/+/4558c2885e618557a674660aff57404d25537070
crbug.com / 762930
github.com / Bo0oM/CVE-2017-5124
security.gentoo.org / glsa/201710-24
debian.org / security/2017/dsa-4020
reddit.com / r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124
securityfocus.com / bid/101482