Vulnerability record · CVE-2017-8755 · published 13 September 2017
CVE-2017-8755: Microsoft Edge scripting engine memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge mishandles objects in memory in its scripting engine, producing a memory corruption condition (CWE-119). An attacker who gets a user to load crafted content in Edge can run code in that user's context, which matters because the browser runs with the user's privileges and the flaw affects Windows 10 1511, 1607, 1703 and Windows Server 2016.
Description
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser with public exploit code and very high EPSS, though exploitation requires user interaction and the affected Windows builds are old.
What it is
Microsoft Edge mishandles objects in memory in its scripting engine, producing a memory corruption condition (CWE-119). An attacker who gets a user to load crafted content in Edge can run code in that user's context, which matters because the browser runs with the user's privileges and the flaw affects Windows 10 1511, 1607, 1703 and Windows Server 2016.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Depending on that user's rights, the attacker could read or modify data, install software, or pivot further into the host.
Attack surface
Reached over the network through the Edge scripting engine, but the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), meaning the victim must open or view attacker-supplied content in Edge. No authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71272, 99.4th percentile) and a public Exploit-DB entry (42766) exists, so working exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-8755 on all affected Windows 10 and Windows Server 2016 systems.
- Upgrade or migrate off the affected Windows 10 builds (1511, 1607, 1703) where feasible, since they are long out of support.
- Enforce browser hardening: block untrusted sites, restrict script execution where possible, and keep Edge and its dependencies current.
- Reduce impact by running users without local administrator rights and applying exploit protection features to browser processes.
Detection
- Monitor for Edge (MicrosoftEdge.exe) crashes or abnormal child processes spawned from the browser, which can indicate scripting engine exploitation.
- Hunt for suspicious processes or network connections originating from Edge, especially those writing to user-writable directories or launching command interpreters.
- Review proxy and DNS logs for known exploit-hosting or malvertising domains delivering Edge-targeted exploit pages.
- Correlate endpoint telemetry for memory corruption indicators in scripting engine modules with subsequent process creation events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100778 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8755 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42766/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100778 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039342 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8755 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42766/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8755 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8755), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.