CVE-2017-5124 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome's Blink rendering engine prior to version 62.0.3202.62, specifically affecting how MHTML pages were handled. This flaw allowed a remote attacker to inject arbitrary scripts or HTML by crafting a malicious MHTML page, impacting Google Chrome and Debian Linux distributions. With a CVSS score of 6.1 (Medium), this vulnerability is exploitable over the network with low attack complexity, requiring user interaction. A successful exploit could lead to limited confidentiality and integrity impacts, allowing attackers to potentially steal sensitive information or deface websites. While not listed on CISA's KEV catalog, exploit code for this vulnerability (EDB-45867) is publicly available. The CVE has garnered significant community discussion and media coverage, indicating a high level of awareness despite its inactive status on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 62.0.3202.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.