Vulnerability record · CVE-2017-11870 · published 15 November 2017
CVE-2017-11870: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Chakracore
CVE-2017-11870 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge on Windows 10 1703, 1709 and Windows Server 1709. Successful exploitation lets an attacker run code with the same rights as the current user, so the impact depends on the privileges of the browsing user.
Description
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11871, and CVE-2017-11873.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5, public exploit code, and a very high EPSS score make this a serious risk despite the lack of KEV listing.
What it is
CVE-2017-11870 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge on Windows 10 1703, 1709 and Windows Server 1709. Successful exploitation lets an attacker run code with the same rights as the current user, so the impact depends on the privileges of the browsing user.
Impact
An attacker can corrupt memory in the scripting engine and execute arbitrary code in the context of the current user. If that user has administrative rights, the attacker can take full control of the system.
Attack surface
The vulnerability is reached over the network through a crafted web page rendered by Microsoft Edge or content processed by ChakraCore. No authentication is required, but user interaction is needed because the victim must open or view the malicious content.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.59642 (99th percentile) and a public Exploit-DB entry (43182) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11870.
- Upgrade or remove unsupported Windows 10 1703/1709 and Windows Server 1709 systems.
- Restrict or disable Microsoft Edge and ChakraCore-based scripting where not required.
- Enforce least privilege so browsing users do not run with administrative rights.
- Block known malicious sites and untrusted script content at the network and email layers.
Detection
- Monitor for Microsoft Edge or ChakraCore process crashes that may indicate memory corruption attempts.
- Hunt for suspicious child processes spawned by Edge or ChakraCore, such as script interpreters or command shells.
- Review proxy and DNS logs for access to known exploit or malicious hosting domains.
- Use EDR to alert on anomalous memory operations or code execution originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101731 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11870 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43182/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101731 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039780 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11870 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43182/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-11870 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11870), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.