CVE-2017-8496 is a memory corruption vulnerability in Microsoft Edge affecting Windows 10 version 1607 and Windows Server 2016, allowing an attacker to execute arbitrary code in the context of the current user. Rated 7.5 HIGH, exploitation requires user interaction (e.g., visiting a malicious website) and has high impact on confidentiality, integrity, and availability. While not actively exploited in the wild and not on the KEV catalog, a public proof-of-concept for a type confusion exploit (EDB-42246) exists, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.