CVE-2017-8605 is a critical memory corruption vulnerability in the Microsoft Edge JavaScript engine affecting Windows 10 and Windows Server 2016. An attacker can achieve arbitrary code execution in the context of the current user by crafting a malicious website that exploits how Edge handles objects in memory. This vulnerability carries a CVSSv3 score of 7.5 (High), indicating a significant impact with high confidentiality, integrity, and availability compromise, requiring user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.