Vulnerability record · CVE-2017-11764 · published 13 September 2017
CVE-2017-11764: Microsoft Edge Scripting Engine Memory Corruption RCE
Microsoft · Edge
Microsoft Edge's scripting engine mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Successful exploitation lets code run in the context of the current user, so impact scales with the privileges of whoever is browsing.
Description
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, and CVE-2017-8756.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with a public exploit and very high EPSS, though no KEV listing or confirmed in-the-wild use is recorded.
What it is
Microsoft Edge's scripting engine mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Successful exploitation lets code run in the context of the current user, so impact scales with the privileges of whoever is browsing.
Impact
An attacker gains arbitrary code execution as the current user, which can lead to data theft, installation of malware, or full compromise of the browsing session's user context.
Attack surface
Reached over the network via a crafted web page or content rendered by Edge; the CVSS vector (AV:N/PR:N/UI:R) indicates no authentication is needed but user interaction (visiting or opening the malicious content) is required.
Exploitation
A public exploit exists (Exploit-DB 42765) and EPSS is high at 0.644 (99th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record here.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11764.
- Upgrade or migrate off Windows 10 1607/1703 and Windows Server 2016 Edge builds that are no longer supported.
- Enforce a modern, supported browser as the default and restrict legacy Edge usage where possible.
- Keep exploit mitigation features (e.g., Windows Defender Exploit Guard/ACG) enabled on affected endpoints.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal child process creation following web browsing.
- Hunt for exploit-related network artifacts or known Exploit-DB 42765 payload patterns in proxy/IDS logs.
- Review endpoint telemetry for suspicious process injection or script-engine-related memory anomalies on affected Windows versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100726 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11764 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42765/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100726 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11764 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42765/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11764 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11764), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.