Vulnerability record · CVE-2017-8729 · published 13 September 2017
CVE-2017-8729: Microsoft Edge scripting engine memory corruption allows code execution
Microsoft · Edge
Microsoft Edge on Windows 10 1703 mishandles objects in memory in its scripting engine, a memory corruption flaw (CWE-119). An attacker who gets a user to load crafted content can run code in that user's context, so the flaw matters wherever Edge is used for browsing untrusted pages.
Description
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser with public exploit code and very high EPSS, though it requires user interaction and affects an old, unsupported platform.
What it is
Microsoft Edge on Windows 10 1703 mishandles objects in memory in its scripting engine, a memory corruption flaw (CWE-119). An attacker who gets a user to load crafted content can run code in that user's context, so the flaw matters wherever Edge is used for browsing untrusted pages.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the current user. That permits data theft, installation of further malware, or further compromise of the host within the user's rights.
Attack surface
The CVSS vector is network-reachable (AV:N) with no privileges required (PR:N) but user interaction required (UI:R), meaning the victim must open or view attacker-controlled content in Edge. No authentication is needed on the attacker's side.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.72171, 99.4th percentile) and an Exploit-DB entry (42763) is referenced, indicating public exploit code exists.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8729.
- Upgrade or migrate off Windows 10 1703 and legacy Edge, which are no longer supported.
- Enforce browser isolation or block untrusted web content for users who must keep Edge.
- Reduce user exposure by restricting browsing to trusted sites and disabling unnecessary scripting content.
- Monitor for and remove unpatched Edge installations from managed endpoints.
Detection
- Hunt for Edge (MicrosoftEdge.exe) crashes or abnormal child processes spawned from the browser.
- Monitor for exploit-related network fetches of known PoC or malicious pages tied to this CVE.
- Review endpoint telemetry for code execution or persistence actions originating from Edge processes.
- Check patch inventory for Windows 10 1703 hosts missing the September 2017 Edge update.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100733 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8729 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42763/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100733 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8729 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42763/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8729 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8729), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.