CVE-2017-8671 is a critical memory corruption vulnerability in Microsoft Edge, affecting Windows 10 (versions 1511, 1607, 1703) and Windows Server 2016. This flaw allows an attacker to execute arbitrary code in the context of the current user by exploiting how the browser's JavaScript engine handles objects in memory. With a CVSSv3 score of 7.5 (High), the vulnerability requires user interaction (e.g., visiting a malicious website) and has high impact on confidentiality, integrity, and availability. Its EPSS score of 0.81883 indicates a high probability of exploitation. While not listed on CISA's KEV catalog, an ExploitDB entry (EDB-42475) details a Chakra JavaScript engine vulnerability related to 'JavascriptFunction::EntryCall'. Community discussion and media coverage are present, suggesting awareness of this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.