CVE-2018-0861 is a remote code execution vulnerability in Microsoft Edge affecting Windows 10 (versions 1607, 1703) and Windows Server 2016. It stems from how the scripting engine handles objects in memory, leading to memory corruption. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a high potential for impact with high confidentiality, integrity, and availability compromise, though it requires user interaction and has high attack complexity. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, and it is not listed in CISA's KEV catalog. Despite limited community discussion, it received media coverage during Microsoft's February Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.