Vulnerability record · CVE-2017-8670 · published 8 August 2017
CVE-2017-8670: Microsoft Edge JavaScript engine memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge on Windows 10 1607, 1703 and Windows Server 2016 mishandles objects in memory in its JavaScript engine, causing a memory corruption condition. A remote attacker who gets a user to load crafted content can run arbitrary code in the context of the current user.
Description
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely used browser with public exploit code and very high EPSS, though exploitation requires user interaction and the affected builds are dated.
What it is
Microsoft Edge on Windows 10 1607, 1703 and Windows Server 2016 mishandles objects in memory in its JavaScript engine, causing a memory corruption condition. A remote attacker who gets a user to load crafted content can run arbitrary code in the context of the current user.
Impact
Successful exploitation gives the attacker code execution with the privileges of the logged-in user, enabling data theft, installation of malware, or further compromise of the host.
Attack surface
Reached over the network through the browser rendering crafted content; the CVSS vector shows no privileges required but user interaction is required, so the victim must open or view attacker-controlled content in Edge.
Exploitation
Not listed in CISA KEV, but EPSS is 0.68729 (99.3rd percentile) and a public Exploit-DB entry (42477) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8670.
- Upgrade or migrate off unsupported Windows 10 1607/1703 builds and keep Edge and Windows fully patched.
- Restrict browsing to trusted sites and block untrusted web content where feasible.
- Run users with least privilege and enable exploit protection features such as Control Flow Guard and ACG where supported.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal process terminations that may indicate memory corruption attempts.
- Hunt for child processes spawned by Edge, especially script interpreters or command shells, which are unusual for normal browsing.
- Review proxy and DNS logs for access to known exploit-hosting or malicious sites delivering browser exploit content.
- Correlate endpoint telemetry for suspicious memory allocation or code injection activity originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100070 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039094 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8670 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42477/ | |
| http://www.securityfocus.com/bid/100070 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039094 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8670 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42477/ |
Track CVE-2017-8670 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8670), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.