CVE-2017-8755 is a critical scripting engine memory corruption vulnerability in Microsoft Edge affecting Windows 10 and Server 2016, allowing arbitrary code execution in the context of the current user. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this vulnerability can be exploited remotely with high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. While not listed in CISA's KEV catalog, an ExploitDB entry exists, and it garnered significant community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's September Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.