CVE-2017-11889: Buffer Overflow
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11889?
CVE-2017-11889 has a high severity rating due to the potential for an attacker to execute arbitrary code.
How do I fix CVE-2017-11889?
To fix CVE-2017-11889, update Microsoft ChakraCore to version 1.7.5 or higher.
Which systems are affected by CVE-2017-11889?
CVE-2017-11889 affects Microsoft Edge and earlier versions of Windows 10 including 1511, 1607, 1703, and 1709.
What kind of attacks can exploit CVE-2017-11889?
CVE-2017-11889 can be exploited to execute arbitrary code in the context of the current user.
Is CVE-2017-11889 present in Windows Server 2016?
No, CVE-2017-11889 is not present in Windows Server 2016.