CVE-2017-8752: Buffer Overflow
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are affected?
The affected platforms listed are Microsoft Windows 10 versions 1511, 1607, and 1703, plus Windows Server 2016, when using Microsoft Edge.
What does exploitation require?
The attacker can be remote and does not need prior privileges, but exploitation requires user interaction. Successful exploitation results in arbitrary code execution in the context of the current user.
Is a fix available?
Yes. A patch is available; apply the relevant Microsoft security update for the affected Windows and Edge environment.