CVE-2017-8637 describes a security feature bypass vulnerability in Microsoft Edge on Windows 10 1703, allowing an attacker to bypass Arbitrary Code Guard (ACG) due to how Edge's JIT compiler accesses memory. This medium-severity vulnerability has a CVSS score of 5.3, indicating a network-based attack with high attack complexity and requiring user interaction, but could lead to high integrity impact. While no public exploit code or active exploitation is reported, its EPSS score suggests a higher-than-average exploitability likelihood compared to most CVEs, and it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.