CVE-2017-8608: Buffer Overflow
Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8596, CVE-2017-8610, CVE-2017-8601, CVE-2017-8618, CVE-2017-8619, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8595, CVE-2017-8606, CVE-2017-8607, and CVE-2017-8609
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8608?
CVE-2017-8608 has a critical severity rating due to its potential to allow execution of arbitrary code.
How do I fix CVE-2017-8608?
To fix CVE-2017-8608, update your Microsoft Edge or Internet Explorer browser to the latest version provided by Microsoft.
Which software versions are affected by CVE-2017-8608?
CVE-2017-8608 affects Microsoft Edge and various versions of Internet Explorer, as well as Windows Server 2008, Windows 8.1, and several Windows 10 releases.
What type of attacks can CVE-2017-8608 facilitate?
CVE-2017-8608 can facilitate remote code execution attacks, allowing attackers to execute code in the context of the current user.
Is there a workaround for CVE-2017-8608?
While applying the latest updates is the recommended approach, temporary workarounds may include disabling JavaScript in the browser settings.