CVE-2017-8638 is a critical memory corruption vulnerability in Microsoft Edge on Windows 10 1703, allowing arbitrary code execution in the context of the current user due to flaws in how JavaScript engines handle objects in memory. This vulnerability carries a high CVSS score of 7.5, indicating a significant risk with a network attack vector, high impact on confidentiality, integrity, and availability, but requiring user interaction and high attack complexity. Despite its severity, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public awareness or active threat intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.