CVE-2017-8647 is a scripting engine memory corruption vulnerability in Microsoft Edge on Windows 10 version 1703, allowing an attacker to execute arbitrary code in the context of the current user. This high-severity vulnerability (CVSS 7.5) requires user interaction and a high attack complexity, but successful exploitation could lead to full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, its EPSS score indicates a higher than average probability of exploitation. Community discussion and media coverage are minimal, suggesting limited public attention despite its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.