CVE-2017-8756: Buffer Overflow
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, and CVE-2017-11764.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are affected?
The affected platforms are Windows 10 Gold, version 1511, version 1607, and version 1703, plus Windows Server 2016, when Microsoft Edge is present.
What does an attacker need to exploit this issue?
The attacker can be remote and does not need prior privileges, but exploitation requires user interaction. Successful exploitation allows arbitrary code execution in the context of the current user.
How urgent is remediation?
A patch is available. The issue is rated high with a CVSS v3.0 score of 7.6 and can affect confidentiality, integrity, and availability.