CVE-2017-8757 is a remote code execution vulnerability in Microsoft Edge affecting Windows 10 and Windows Server 2016, stemming from how Edge handles objects in memory. This high-severity vulnerability (CVSS 7.5) can be exploited remotely with high attack complexity, requiring user interaction, and allows an attacker to execute arbitrary code with the privileges of the current user, leading to full compromise of confidentiality, integrity, and availability. While there is no known public exploit code or Metasploit module, the vulnerability has garnered some community discussion and media coverage, indicating awareness. It is not listed in the KEV catalog and is currently inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.