Vulnerability record · CVE-2017-11911 · published 12 December 2017
CVE-2017-11911: Microsoft Scripting Engine Memory Corruption in ChakraCore and Edge
Microsoft · Edge
CVE-2017-11911 is a memory corruption flaw in how the Microsoft scripting engine handles objects in memory, affecting ChakraCore and the Edge browser on Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016. Successful exploitation lets an attacker run arbitrary code in the context of the current user, so the impact is bounded by that user's privileges.
Description
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityA public exploit exists and EPSS is very high, but exploitation requires user interaction and the flaw is not in CISA KEV.
What it is
CVE-2017-11911 is a memory corruption flaw in how the Microsoft scripting engine handles objects in memory, affecting ChakraCore and the Edge browser on Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016. Successful exploitation lets an attacker run arbitrary code in the context of the current user, so the impact is bounded by that user's privileges.
Impact
An attacker gains arbitrary code execution as the logged-in user, which can lead to data theft, installation of malware, or full account compromise if the user has administrative rights.
Attack surface
Reached over the network via a crafted web page or script that the scripting engine processes; the CVSS vector shows no privileges required but user interaction required, meaning the victim must open or view the malicious content.
Exploitation
A public exploit exists on Exploit-DB, and EPSS is 0.6546 (99.2nd percentile), indicating high predicted exploitation activity; the CVE is not listed in CISA KEV.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for the affected Windows and ChakraCore versions.
- Upgrade or replace unsupported Windows 10 builds (1511, 1607, 1703, 1709) that no longer receive security fixes.
- Restrict or disable unnecessary scripting engine and browser components where operationally feasible.
- Enforce browser isolation or application allowlisting to reduce exposure to malicious web content.
- Educate users not to open untrusted links or attachments that could deliver crafted script content.
Detection
- Monitor for browser or scripting engine crashes, especially repeated faults in Edge or ChakraCore processes.
- Hunt for suspicious child processes spawned by browser processes, which can indicate successful exploitation.
- Review proxy and DNS logs for known exploit-hosting domains or delivery of malicious script content.
- Correlate endpoint telemetry for memory corruption indicators and unusual code execution in user context.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102087 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11911 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43468/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102087 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11911 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43468/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11911 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11911), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.