Vulnerability record · CVE-2017-8636 · published 8 August 2017
CVE-2017-8636: Microsoft browser JavaScript engine memory corruption allows code execution
Microsoft · Internet Explorer
Microsoft Internet Explorer and Edge JavaScript engines mishandle objects in memory when rendering content, a memory corruption flaw (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. It affects a broad set of Windows client and server releases, and public exploit code exists, so unpatched browser users are at real risk.
Description
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityPublic exploit code and a very high EPSS score make this readily weaponizable, though the CVSS attack complexity is high and user interaction is required.
What it is
Microsoft Internet Explorer and Edge JavaScript engines mishandle objects in memory when rendering content, a memory corruption flaw (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. It affects a broad set of Windows client and server releases, and public exploit code exists, so unpatched browser users are at real risk.
Impact
An attacker who triggers the flaw gains arbitrary code execution with the privileges of the logged-in user, which can lead to full system compromise if that user has administrative rights.
Attack surface
Reached over the network via a crafted web page or content that the browser's JavaScript engine renders; the CVSS vector requires user interaction (UI:R) and no authentication (PR:N), so a victim must visit or open attacker-controlled content.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.721, 99.4th percentile) and multiple Exploit-DB entries are tagged as exploits, indicating public exploit code is available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8636 as the first action.
- Upgrade or retire unsupported platforms (Windows 7 SP1, Windows 8.1, Windows RT 8.1, Server 2008 R2, Server 2012/R2) that no longer receive browser fixes.
- Enforce use of a current, fully patched browser and disable legacy Internet Explorer where business needs allow.
- Reduce exposure by blocking untrusted web content and restricting high-risk browsing through network or proxy controls.
Detection
- Hunt for browser processes (iexplore.exe, MicrosoftEdge.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for normal browsing.
- Monitor for crashes or exploit artifacts in the JavaScript engine, including repeated browser process terminations tied to the same user or URL.
- Review proxy and web logs for known exploit-hosting domains or pages delivering the Exploit-DB payloads associated with this CVE.
- Alert on suspicious memory-protection changes or shellcode-like behavior in browser process memory where endpoint telemetry supports it.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-8636 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.