Vulnerability record · CVE-2017-11841 · published 15 November 2017
CVE-2017-11841: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Chakracore
Microsoft Edge and ChakraCore mishandle objects in memory in the scripting engine, causing a memory corruption condition (CWE-119). An attacker who gets a victim to load crafted content can corrupt memory and run code in the context of the current user. The flaw affects Windows 10 (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016/1709.
Description
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with high confidentiality, integrity and availability impact, a public exploit, and very high EPSS, though exploitation requires user interaction and high attack complexity.
What it is
Microsoft Edge and ChakraCore mishandle objects in memory in the scripting engine, causing a memory corruption condition (CWE-119). An attacker who gets a victim to load crafted content can corrupt memory and run code in the context of the current user. The flaw affects Windows 10 (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016/1709.
Impact
An attacker gains the same user rights as the current user, which means code execution at that privilege level. If the logged-on user is an administrator, the attacker can take full control of the affected system.
Attack surface
Reached over the network through the browser or scripting engine when a user opens a crafted page or document; the CVSS vector shows no privileges required but user interaction required (UI:R), and the high attack complexity (AC:H) indicates a non-trivial memory layout condition.
Exploitation
Not listed in CISA KEV, but EPSS is 0.59642 (99th percentile) and a public Exploit-DB entry (43181) exists, so exploitation is feasible and public tooling is available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11841 on all affected Windows 10 and Windows Server builds.
- Upgrade or retire unsupported Windows 10 versions (Gold, 1511, 1607, 1703, 1709) that no longer receive security fixes.
- Keep Edge and ChakraCore-based components current, and restrict use of legacy scripting engines where possible.
- Reduce exposure by enforcing least privilege so browser compromise does not yield administrative rights.
Detection
- Monitor for Edge or scripting engine processes spawning unexpected child processes or writing to unusual paths.
- Hunt for crashes in Edge/ChakraCore modules (e.g., chakra.dll) that precede suspicious process activity.
- Review proxy and DNS logs for known exploit-hosting domains tied to public PoCs for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101733 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11841 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43181/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101733 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11841 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43181/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-11841 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11841), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.