Vulnerability record · CVE-2017-11812 · published 13 October 2017
CVE-2017-11812: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Chakracore
Microsoft Edge and ChakraCore on Windows 10 (1511, 1607, 1703) and Windows Server 2016 mishandle objects in memory in the scripting engine, causing memory corruption. An attacker who gets a user to load crafted content can run code as that user, so the flaw matters for any environment still running these builds.
Description
ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11812, and CVE-2017-11821.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with high confidentiality, integrity and availability impact and a very high EPSS percentile, though exploitation requires user interaction and no KEV listing exists.
What it is
Microsoft Edge and ChakraCore on Windows 10 (1511, 1607, 1703) and Windows Server 2016 mishandle objects in memory in the scripting engine, causing memory corruption. An attacker who gets a user to load crafted content can run code as that user, so the flaw matters for any environment still running these builds.
Impact
Successful exploitation gives arbitrary code execution in the context of the current user, which can lead to data theft, installation of malware, or further compromise of the host depending on user privileges.
Attack surface
Reached over the network through crafted web content or a document rendered by the affected scripting engine; the CVSS vector shows no privileges required but user interaction required, so a victim must open or view the malicious content.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.4726 (98.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for CVE-2017-11812.
- Upgrade or remove unsupported Windows 10 1511/1607/1703 and Windows Server 2016 builds that no longer receive fixes.
- Keep Edge and ChakraCore-based components current and restrict use of legacy scripting hosts where possible.
- Enforce email and web filtering to block delivery of crafted pages or documents to users.
Detection
- Monitor for Edge or ChakraCore process crashes and unexpected child processes spawned from browser processes.
- Hunt for suspicious script or document files opened shortly before abnormal process creation on affected hosts.
- Review endpoint telemetry for code execution originating from browser or scripting engine processes outside normal behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101139 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039529 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11812 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/101139 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039529 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11812 | PatchVendor Advisory |
Track CVE-2017-11812 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11812), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.