Vulnerability record · CVE-2017-11799 · published 13 October 2017
CVE-2017-11799: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Chakracore
ChakraCore and the Microsoft Edge scripting engine mishandle objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Microsoft rates it 7.5 HIGH, and because the scripting engine runs in the browser process, successful corruption can lead to code execution in the user's context.
Description
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with high confidentiality, integrity and availability impact, a public exploit and very high EPSS, though exploitation requires user interaction and high attack complexity.
What it is
ChakraCore and the Microsoft Edge scripting engine mishandle objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. Microsoft rates it 7.5 HIGH, and because the scripting engine runs in the browser process, successful corruption can lead to code execution in the user's context.
Impact
An attacker who triggers the flaw can execute arbitrary code with the privileges of the current user. On a typical workstation that means the attacker gains the user's access to data, credentials and network resources.
Attack surface
Reached over the network (AV:N) through the scripting engine, most likely by a user opening a malicious or compromised web page in Edge. The vector requires user interaction (UI:R) and no privileges (PR:N), and the high attack complexity (AC:H) indicates a non-trivial trigger.
Exploitation
Not listed in CISA KEV, but EPSS is 0.63675 (99.2nd percentile) and a public Exploit-DB entry (42998) exists, so working exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11799 as the first action.
- Upgrade or retire Windows 10 Gold, 1511, 1607, 1703 and Windows Server 2016 systems that cannot receive the patch.
- Keep Edge and any ChakraCore-based application current, since the flaw is in the shared scripting engine.
- Reduce exposure by restricting browsing to trusted sites and blocking known exploit-hosting domains at the network edge.
Detection
- Hunt for Edge or ChakraCore processes spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for a browser.
- Monitor for crashes or repeated faults in Edge/ChakraCore modules that could indicate exploitation attempts.
- Alert on network requests to domains or URLs associated with the public Exploit-DB proof of concept.
- Review endpoint telemetry for unusual memory-protection changes or shellcode-like behavior in browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101126 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039529 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11799 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42998/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101126 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039529 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11799 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42998/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-11799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11799), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.