Vulnerability record · CVE-2017-8731 · published 13 September 2017
CVE-2017-8731: Microsoft Edge memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge on Windows 10 1607 and Windows Server 2016 mishandles objects in memory, producing a memory corruption condition (CWE-119). A remote attacker can trigger it through crafted content and run code as the current user, so the flaw matters wherever Edge is used for browsing or rendering untrusted web content.
Description
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8734, CVE-2017-8751, and CVE-2017-11766.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 3.0 is 7.5 (HIGH), a public exploit exists, and EPSS is near the top percentile, though exploitation requires user interaction and no KEV listing is present.
What it is
Microsoft Edge on Windows 10 1607 and Windows Server 2016 mishandles objects in memory, producing a memory corruption condition (CWE-119). A remote attacker can trigger it through crafted content and run code as the current user, so the flaw matters wherever Edge is used for browsing or rendering untrusted web content.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the logged-in user, with high confidentiality, integrity and availability impact. The attacker does not gain system privileges directly but inherits the user's data and permissions.
Attack surface
The vector is network-reachable (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), meaning the victim must open or view attacker-controlled content in Edge. No authentication is needed on the target.
Exploitation
CISA KEV does not list this CVE, but a public Exploit-DB entry (42758) exists and EPSS is high at roughly 0.516 (98.9th percentile), indicating meaningful exploitation likelihood.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8731.
- Upgrade or migrate off Windows 10 1607 and Windows Server 2016 Edge builds that are no longer serviced.
- Enforce browsing in a modern, fully patched browser and block legacy Edge where feasible.
- Reduce exposure by restricting untrusted web content and applying network filtering for known malicious hosts.
- Run browsing sessions with least privilege and enable exploit mitigations such as ASLR and DEP.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal terminations that may indicate memory corruption attempts.
- Hunt for child processes spawned by Edge, such as script interpreters or command shells, which are atypical for normal browsing.
- Review proxy and DNS logs for connections to hosts associated with known exploit pages or malvertising.
- Correlate endpoint telemetry for suspicious memory writes or code execution originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100735 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8731 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42758/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100735 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8731 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42758/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8731 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8731), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.