CVE-2017-8603 is a critical memory corruption vulnerability affecting Microsoft Edge on Windows 10 and Windows Server 2016. It allows an attacker to execute arbitrary code in the context of the current user due to improper handling of objects in memory by the JavaScript engine. With a CVSS score of 7.5 (High), exploitation requires user interaction (e.g., clicking a malicious link) but can lead to full compromise of the user's system. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.