First published: Wed Nov 15 2017(Updated: )
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, and CVE-2017-11871.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
ChakraCore | ||
Microsoft Edge Beta | ||
Windows 10 | ||
Windows 10 | =1511 | |
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Microsoft Windows Server | =1709 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11873 has a severity rating of critical due to the potential for attackers to gain the same user rights as the current user.
To fix CVE-2017-11873, it is recommended to apply the latest security updates provided by Microsoft for the affected software.
CVE-2017-11873 affects Microsoft ChakraCore and Microsoft Edge on various versions of Windows 10 and Windows Server.
Yes, CVE-2017-11873 can be exploited remotely, allowing attackers to execute malicious scripts in the context of the current user.
CVE-2017-11873 can allow an attacker to gain the same user rights as the current user, potentially leading to unauthorized access and data breaches.