Vulnerability record · CVE-2017-11909 · published 12 December 2017
CVE-2017-11909: Microsoft Chakra Scripting Engine Memory Corruption RCE
Microsoft · Edge
ChakraCore and the Chakra scripting engine in Windows 10 (1511, 1607, 1703, 1709) and Windows Server 2016 mishandle objects in memory, causing a memory corruption condition (CWE-119). An attacker who gets a victim to load crafted content can run code in the context of the current user, which matters because the scripting engine is reachable from normal browsing and document rendering.
Description
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a public exploit and very high EPSS, though exploitation requires user interaction and high attack complexity and it is not in KEV.
What it is
ChakraCore and the Chakra scripting engine in Windows 10 (1511, 1607, 1703, 1709) and Windows Server 2016 mishandle objects in memory, causing a memory corruption condition (CWE-119). An attacker who gets a victim to load crafted content can run code in the context of the current user, which matters because the scripting engine is reachable from normal browsing and document rendering.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the logged-on user. That allows data theft, installation of malware, or further lateral movement on the host.
Attack surface
Reached over the network (AV:N) through crafted script content processed by the Chakra engine, typically in a browser or script host. No privileges are required (PR:N) but user interaction is required (UI:R), and the attack complexity is rated high (AC:H).
Exploitation
A public exploit exists (Exploit-DB 43467), and EPSS is high at 0.6546 (99.2nd percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11909; this is the primary fix.
- Upgrade or remove unsupported Windows 10 builds (1511, 1607, 1703, 1709) and keep Windows Server 2016 patched.
- Keep ChakraCore-based applications updated to a fixed release or migrate off ChakraCore where possible.
- Reduce exposure by restricting browsing to trusted sites and blocking untrusted script content at the network or email gateway.
- Run users with least privilege and enable exploit protection features such as Control Flow Guard and Arbitrary Code Guard where supported.
Detection
- Monitor for crashes or abnormal terminations of browser and script host processes (e.g., Edge, ChakraCore hosts) that could indicate memory corruption attempts.
- Alert on child processes spawned by browsers or script hosts, especially command shells or scripting engines, which may indicate post-exploitation.
- Hunt for known public exploit artifacts tied to Exploit-DB 43467 in web proxy, email, or endpoint logs.
- Track unpatched Windows 10 1511/1607/1703/1709 and Server 2016 hosts via vulnerability or asset inventory scans.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102085 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11909 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43467/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102085 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11909 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43467/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11909 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11909), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.