CVE-2017-8594 is a memory corruption vulnerability in Internet Explorer on Windows 8.1, RT 8.1, and Server 2012 R2. This flaw allows an unauthenticated, remote attacker to execute arbitrary code in the context of the current user due to improper object access in memory. Rated with a CVSS score of 7.5 (High), successful exploitation could lead to high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. While not listed in CISA's KEV catalog, a proof-of-concept exploit exists on ExploitDB, and it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.