CVE-2017-8611 is a spoofing vulnerability in Microsoft Edge affecting Windows 10 versions Gold, 1511, 1607, and 1703, as well as Windows Server 2016. An attacker could exploit this by crafting a malicious website to spoof web content. Rated as MEDIUM severity with a CVSS score of 6.5, this vulnerability requires user interaction (UI:R) and could lead to high integrity impact (I:H) without affecting confidentiality or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.