Vulnerability record · CVE-2017-11918 · published 12 December 2017
CVE-2017-11918: Microsoft Edge and ChakraCore scripting engine memory corruption
Microsoft · Edge
CVE-2017-11918 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 and Windows Server 2016. Successful exploitation lets an attacker run code with the same rights as the current user, so impact scales with the privileges of the browsing user.
Description
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, and CVE-2017-11930.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with high EPSS and a public exploit reference make this a serious risk for unpatched Edge and ChakraCore users, though it is not in CISA KEV.
What it is
CVE-2017-11918 is a memory corruption flaw in how the ChakraCore scripting engine handles objects in memory, affecting Microsoft Edge and ChakraCore on Windows 10 and Windows Server 2016. Successful exploitation lets an attacker run code with the same rights as the current user, so impact scales with the privileges of the browsing user.
Impact
An attacker gains the same user rights as the current user, which can mean code execution in the browser's security context. If the user is an administrator, the attacker could take control of the affected system.
Attack surface
Reached over the network via a crafted web page or content processed by the scripting engine, requiring user interaction (UI:R) and no prior authentication (PR:N). The CVSS vector notes high attack complexity (AC:H).
Exploitation
An Exploit-DB entry (43469) is referenced, indicating public exploit code exists. The CVE is not listed in CISA KEV, but EPSS is high at 0.62646 (99.15th percentile).
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com advisory CVE-2017-11918) as the primary fix.
- Upgrade or remove unsupported Windows 10 builds (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016 systems that cannot be patched.
- Restrict or disable the affected scripting engine where feasible and enforce browser hardening.
- Run users with least privilege so a successful exploit yields limited rights.
- Block known exploit sources and monitor for delivery of crafted web content.
Detection
- Monitor for crashes or abnormal behavior in Microsoft Edge and ChakraCore processes.
- Hunt for known exploit code or indicators tied to Exploit-DB 43469 in web and endpoint telemetry.
- Review proxy and network logs for delivery of crafted pages targeting the scripting engine.
- Track unpatched Windows 10 and Windows Server 2016 assets against the vendor advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102089 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11918 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43469/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102089 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039990 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11918 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43469/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-11918 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11918), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.