CVE-2017-8649 is a scripting engine memory corruption vulnerability in Microsoft Edge affecting Windows 10 and Windows Server 2016, allowing arbitrary code execution in the context of the current user. With a CVSS score of 7.5 (HIGH), it requires user interaction and high attack complexity, but successful exploitation can lead to full compromise of the user's system. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, including a mention in a BleepingComputer article about Microsoft's September Patch Tuesday. The vulnerability is not listed in CISA's KEV catalog and is currently considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.