Vulnerability record · CVE-2017-11840 · published 15 November 2017
CVE-2017-11840: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Chakracore
CVE-2017-11840 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 and Windows Server 2016/1709. Successful exploitation lets an attacker execute code with the same rights as the current user, so impact scales with the privileges of whoever is browsing.
Description
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with a public exploit and very high EPSS percentile, though exploitation requires user interaction and high attack complexity.
What it is
CVE-2017-11840 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 and Windows Server 2016/1709. Successful exploitation lets an attacker execute code with the same rights as the current user, so impact scales with the privileges of whoever is browsing.
Impact
An attacker gains code execution in the context of the logged-in user, enabling data theft, further compromise of the host, or lateral movement if that user has elevated rights.
Attack surface
Reached over the network through a crafted web page or script processed by Edge or ChakraCore, requiring user interaction (UI:R) but no authentication (PR:N); the CVSS vector notes high attack complexity.
Exploitation
Not listed in CISA KEV, but EPSS is 0.59642 (99th percentile) and a public Exploit-DB entry (43183) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11840.
- Upgrade or retire affected Windows 10 and Windows Server 2016/1709 systems that can no longer be patched.
- Restrict or disable Microsoft Edge and ChakraCore-based script execution where not required.
- Enforce least privilege so browsing occurs under non-administrative accounts.
- Block known exploit hosts and untrusted script content at the network and email layers.
Detection
- Monitor for Edge or ChakraCore process crashes and abnormal memory-corruption behavior on endpoints.
- Hunt for suspicious child processes spawned by browser processes (for example script interpreters or command shells).
- Review proxy and DNS logs for known exploit-hosting domains tied to public PoCs.
- Alert on unexpected outbound connections originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101734 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11840 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43183/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101734 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11840 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43183/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-11840 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.