Vulnerability record · CVE-2017-8734 · published 13 September 2017
CVE-2017-8734: Microsoft Edge memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge mishandles objects in memory, producing a memory corruption condition (CWE-119) that lets an attacker run arbitrary code in the context of the current user. It affects Edge on Windows 10 Gold, 1511, 1607, 1703 and Windows Server 2016. Because the browser runs with user privileges, a successful hit gives code execution at that same level.
Description
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8751, and CVE-2017-11766.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (7.5) with public exploit code and very high EPSS, though no KEV listing or confirmed in-the-wild use in this record.
What it is
Microsoft Edge mishandles objects in memory, producing a memory corruption condition (CWE-119) that lets an attacker run arbitrary code in the context of the current user. It affects Edge on Windows 10 Gold, 1511, 1607, 1703 and Windows Server 2016. Because the browser runs with user privileges, a successful hit gives code execution at that same level.
Impact
An attacker who triggers the flaw gains arbitrary code execution as the current user, which can lead to data theft, further compromise of the host, or installation of additional malware. The CVSS 3.0 vector rates confidentiality, integrity and availability all High.
Attack surface
The vector is network-reachable (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), consistent with a victim visiting a crafted page or opening malicious content in Edge. No authentication is needed beyond the user browsing.
Exploitation
An Exploit-DB entry (42759) exists, indicating public exploit code, and EPSS is high at 0.52537 (98.9th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this data.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8734.
- Upgrade or migrate off unsupported Windows 10 builds (Gold, 1511) and keep Edge and Windows fully patched.
- Enforce browser isolation or sandboxing and block untrusted web content where feasible.
- Reduce reliance on Edge for untrusted browsing until patched, or restrict it via application control.
- Monitor for and block known exploit code tied to this CVE.
Detection
- Hunt for Edge (MicrosoftEdge.exe) crashes or abnormal child process creation, especially spawning script interpreters or system utilities.
- Monitor for exploit-db 42759 signatures or related shellcode patterns in network and endpoint telemetry.
- Review endpoint logs for memory corruption indicators and unexpected code execution originating from browser processes.
- Alert on Edge versions predating the September 2017 patch level in asset inventories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100738 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8734 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42759/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100738 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8734 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42759/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8734 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8734), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.