CVE-2018-8509 is a remote code execution vulnerability in Microsoft Edge, affecting Microsoft Edge and Windows 10, caused by improper memory access. It has a high CVSS score of 7.5, indicating a significant risk due to its network attack vector, high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. There is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available. Despite limited community discussion and media coverage, its EPSS score suggests a higher-than-average likelihood of exploitation compared to most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.