CVE-2017-8674 is a scripting engine memory corruption vulnerability affecting Microsoft Edge on Windows 10 1703, allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability carries a high CVSS score of 7.5, indicating a significant risk due to its potential for high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. While it has a high EPSS score suggesting exploitability, there is no evidence of active exploitation, nor are public exploit tools like Metasploit or ExploitDB available. Community discussion and media coverage are minimal, suggesting limited public attention despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.