Vulnerability record · CVE-2017-8671 · published 8 August 2017
CVE-2017-8671: Microsoft Edge scripting engine memory corruption allows code execution
Microsoft · Edge
Microsoft Edge's JavaScript engine mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. It affects Edge on Windows 10 1511, 1607, 1703, and Windows Server 2016, and is one of a large batch of similar scripting engine flaws patched together. Because the browser runs with user privileges, successful exploitation gives code execution in that user's context.
Description
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8672, and CVE-2017-8674.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser with public exploit code and very high EPSS, though it requires user interaction and affects older Windows builds.
What it is
Microsoft Edge's JavaScript engine mishandles objects in memory, causing a memory corruption condition (CWE-119) that can be triggered by crafted content. It affects Edge on Windows 10 1511, 1607, 1703, and Windows Server 2016, and is one of a large batch of similar scripting engine flaws patched together. Because the browser runs with user privileges, successful exploitation gives code execution in that user's context.
Impact
An attacker can execute arbitrary code in the context of the current user, potentially leading to full compromise of the browsing session and any data or credentials that user can reach.
Attack surface
Reached over the network through the browser rendering crafted JavaScript content; the CVSS vector shows no privileges required but user interaction required, meaning the victim must open or view the malicious page.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.693, 99.3rd percentile) and a public Exploit-DB entry (42475) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8671.
- Upgrade or migrate off unsupported Windows 10 builds (1511, 1607, 1703) and keep Edge and Windows fully patched.
- Enforce browser hardening: disable or restrict JavaScript where feasible and block untrusted sites via proxy or filtering.
- Reduce impact by running users without local admin rights and enabling exploit protection features such as Control Flow Guard and Arbitrary Code Guard.
- Monitor vendor advisories for the related scripting engine CVEs patched in the same cycle and ensure all are applied.
Detection
- Hunt for Edge (MicrosoftEdge.exe) crashes or abnormal terminations on endpoints, especially correlated with recent browsing to untrusted sites.
- Review proxy and DNS logs for access to known exploit-hosting or malvertising domains around the time of browser crashes.
- Monitor for suspicious child processes spawned by MicrosoftEdge.exe, such as script interpreters or command shells.
- Use EDR to alert on memory corruption indicators or exploit-mitigation events (for example, CFG or ACG violations) in browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100071 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8671 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42475/ | |
| http://www.securityfocus.com/bid/100071 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039095 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8671 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42475/ |
Track CVE-2017-8671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8671), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.