Vulnerability record · CVE-2017-11914 · published 12 December 2017
CVE-2017-11914: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Edge
CVE-2017-11914 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 (1511, 1607, 1703, 1709) and Windows Server 2016. Successful exploitation lets an attacker run code with the same rights as the current user, so the impact scales with the privileges of whoever is browsing.
Description
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with public exploit code and very high EPSS, but exploitation requires user interaction and no KEV listing confirms active campaigns.
What it is
CVE-2017-11914 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 (1511, 1607, 1703, 1709) and Windows Server 2016. Successful exploitation lets an attacker run code with the same rights as the current user, so the impact scales with the privileges of whoever is browsing.
Impact
An attacker gains code execution at the privilege level of the logged-in user, which can mean full control of the account's data and, on admin sessions, the host. No elevation beyond the current user is described.
Attack surface
Reached over the network through a crafted web page or script processed by the Edge/ChakraCore scripting engine, per the AV:N vector. The CVSS vector requires user interaction (UI:R) and no authentication (PR:N), so a victim must open or be directed to malicious content.
Exploitation
An Exploit-DB entry (EDB-43713) is referenced, indicating public exploit code exists, and EPSS is high at 0.626 (99th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Apply the Microsoft security update for CVE-2017-11914 (MSRC advisory) to Edge, ChakraCore and affected Windows 10/Server 2016 builds first.
- Keep Windows and Edge fully patched; these 2017 builds are long out of support, so migrate off Windows 10 1511/1607/1703/1709 and Server 2016 where feasible.
- Restrict or disable ChakraCore-based scripting where it is not required by business applications.
- Enforce browsing controls and block untrusted sites to reduce exposure to crafted pages that trigger the flaw.
- Run users with least privilege so code execution stays confined to a standard account.
Detection
- Monitor for Edge or ChakraCore process crashes and unexpected child processes spawned from browser processes.
- Alert on suspicious script or document content delivered from newly seen or low-reputation domains to Edge users.
- Hunt for post-exploitation behavior from browser processes, such as unusual outbound connections or dropped executables.
- Track endpoint telemetry for known exploit artifacts tied to EDB-43713 in browser memory or script execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102088 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11914 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43713/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102088 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11914 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43713/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11914 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11914), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.