Vulnerability record · CVE-2017-8751 · published 13 September 2017
CVE-2017-8751: Microsoft Edge memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge on Windows 1703 mishandles objects in memory, producing a memory corruption condition (CWE-119). A remote attacker who gets a user to load crafted content can run code in the context of the current user. The flaw is patched by Microsoft and a public exploit exists.
Description
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser with public exploit code and very high EPSS, though exploitation requires user interaction and high attack complexity.
What it is
Microsoft Edge on Windows 1703 mishandles objects in memory, producing a memory corruption condition (CWE-119). A remote attacker who gets a user to load crafted content can run code in the context of the current user. The flaw is patched by Microsoft and a public exploit exists.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the logged-in user, enabling data theft, persistence or further compromise of the host.
Attack surface
Reached over the network (AV:N) through Edge rendering attacker-controlled content; no authentication is required (PR:N) but user interaction is needed (UI:R) for the victim to open or view the crafted page. Attack complexity is rated high (AC:H).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.50373, ~98.9th percentile) and an Exploit-DB entry (43151) is referenced, indicating public exploit code is available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8751.
- Keep Edge and Windows 1703 fully patched; upgrade off end-of-life Windows 1703 builds.
- Restrict or block untrusted web content and enforce browsing protections where feasible.
- Reduce user exposure by limiting administrative rights and applying least privilege on endpoints.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal child processes spawned from the browser.
- Hunt for post-exploitation behavior such as unexpected script interpreters or command shells launched by Edge.
- Review proxy and DNS logs for known exploit-hosting or malicious URLs delivering Edge content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8751 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43151/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039326 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8751 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/43151/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8751 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8751), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.