Vulnerability record · CVE-2017-8641 · published 8 August 2017
CVE-2017-8641: Microsoft browser scripting engine memory corruption allows code execution
Microsoft · Edge
Microsoft Edge and Internet Explorer JavaScript engines mishandle objects in memory, producing a memory corruption condition (CWE-119) that can be triggered while rendering content. Because the flaw sits in the scripting engine, a crafted page can corrupt memory in the browser process and run code as the logged-in user. It affects a broad set of Windows client and server releases listed in the advisory.
Description
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in widely deployed browsers with public exploit code and very high EPSS, though exploitation requires the victim to open a crafted page.
What it is
Microsoft Edge and Internet Explorer JavaScript engines mishandle objects in memory, producing a memory corruption condition (CWE-119) that can be triggered while rendering content. Because the flaw sits in the scripting engine, a crafted page can corrupt memory in the browser process and run code as the logged-in user. It affects a broad set of Windows client and server releases listed in the advisory.
Impact
An attacker who lands the exploit executes arbitrary code in the context of the current user, giving the same rights as that user over the affected system. On a browsing account this can mean data theft, credential access and further lateral movement.
Attack surface
Reached over the network through a browser rendering a malicious or compromised web page; the CVSS vector shows no privileges required but user interaction required, so the victim must open the page. No authentication is needed to deliver the content.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.716 probability, 99.4th percentile) and a public Exploit-DB entry (42465) exists, so working exploit code is publicly available. No ransomware association is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8641 on all affected Windows versions.
- If patching cannot be immediate, restrict or disable legacy Internet Explorer and unpatched Edge usage, and block untrusted script execution where policy allows.
- Keep browsers and the OS on supported builds; the affected Windows 10 and Server versions are long out of support, so migrate off them.
- Enforce least privilege on browsing accounts and block known exploit-hosting domains at the web gateway.
- Use application control or browser isolation to contain rendering of untrusted web content.
Detection
- Monitor for browser processes (iexplore.exe, MicrosoftEdge.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on browser crashes or memory-corruption events in JavaScript engine modules across endpoints.
- Hunt proxy and DNS logs for requests to domains tied to known exploit kits or the Exploit-DB 42465 payload.
- Correlate endpoint telemetry for unusual outbound connections originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100057 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8641 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42465/ | |
| http://www.securityfocus.com/bid/100057 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8641 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42465/ |
Track CVE-2017-8641 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8641), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.