CVE-2017-8640: Buffer Overflow
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are affected?
Affected systems are Microsoft Edge on Windows 10 Gold, version 1511, version 1607, and version 1703, as well as Windows Server 2016.
What must an attacker do to exploit this issue?
An attacker must cause a user to interact with crafted content in Microsoft Edge. The vulnerability is remotely reachable and requires no attacker privileges, but exploitation has high attack complexity and requires user interaction.
What level of access could exploitation provide?
Successful exploitation can allow arbitrary code execution in the context of the current user. The listed impact includes high confidentiality, integrity, and availability impact.
Is a fix available?
Yes. A patch is available for this vulnerability.