CVE-2017-8644 is an information disclosure vulnerability in Microsoft Edge affecting Windows 10 and Windows Server 2016, stemming from how the browser handles objects in memory. Rated Medium severity (CVSS 4.3), it requires user interaction (UI:R) and network access (AV:N) for a successful attack, potentially leading to limited confidentiality impact (C:L). While not actively exploited in the wild, an out-of-bounds read exploit (EDB-42459) exists, and the vulnerability has received some community discussion and media coverage. Its high FAUCET Risk Score of 96/100 indicates a significant potential risk despite the moderate CVSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.