CVE-2017-8660 is a critical memory corruption vulnerability in Microsoft Edge, affecting Windows 10 and Server 2016, which allows remote code execution due to improper handling of objects in the JavaScript engine. With a CVSS score of 8.8 (High), it presents a significant risk as an unauthenticated attacker can achieve full compromise of the user's system with low attack complexity, requiring only user interaction. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media attention. This indicates a potential for future exploitation, despite its inactive status on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.