CVE-2017-8731 is a memory corruption vulnerability in Microsoft Edge affecting Windows 10 version 1607 and Windows Server 2016, allowing an attacker to execute arbitrary code in the context of the current user. With a CVSS score of 7.5 (High), exploitation requires user interaction (e.g., visiting a malicious website) and has high impacts on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a public exploit (EDB-42758) exists, and it has garnered some community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.