Vulnerability record · CVE-2017-8656 · published 8 August 2017
CVE-2017-8656: Microsoft Edge scripting engine memory corruption allows code execution
Microsoft · Edge
Microsoft Edge's JavaScript engine mishandles objects in memory, causing a memory corruption condition (CWE-119) when rendering content. A remote attacker who convinces a user to view crafted content can run arbitrary code in that user's context. The flaw affects Edge on Windows 10 1607, 1703, and Windows Server 2016.
Description
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with high EPSS and a public exploit raise the risk, though exploitation requires user interaction and no KEV listing is present.
What it is
Microsoft Edge's JavaScript engine mishandles objects in memory, causing a memory corruption condition (CWE-119) when rendering content. A remote attacker who convinces a user to view crafted content can run arbitrary code in that user's context. The flaw affects Edge on Windows 10 1607, 1703, and Windows Server 2016.
Impact
Successful exploitation gives the attacker code execution with the privileges of the current user, enabling data theft, installation of malware, or further compromise of the host.
Attack surface
Reached over the network through crafted web content rendered by the Edge JavaScript engine; no authentication is required, but user interaction is needed per the CVSS vector (UI:R), meaning the victim must open or view the malicious page.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.69277, 99.3rd percentile) and a public Exploit-DB entry (42464) exists, indicating exploit code is available.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com advisory CVE-2017-8656) as the first action.
- Upgrade affected Windows 10 1607/1703 and Windows Server 2016 systems to a supported build that includes the fix.
- Restrict or disable Microsoft Edge where it is not required, and enforce a modern supported browser.
- Block known exploit hosts and untrusted script sources at the network and email gateway layers.
- Enable exploit protection features such as Control Flow Guard and mitigations for browser processes.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal child processes spawned from browser processes.
- Alert on suspicious process creation where a browser process is the parent, especially scripting or command interpreters.
- Review proxy and DNS logs for requests to known exploit or malicious content hosts tied to this campaign.
- Correlate endpoint telemetry for memory corruption indicators and unexpected code execution in browser context.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100033 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8656 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42464/ | |
| http://www.securityfocus.com/bid/100033 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8656 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42464/ |
Track CVE-2017-8656 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8656), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.