Versio.io

CVE-2017-11874

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 15-11-2017 04:29
Last modified: - 23-05-2022 07:29
Total changes: - 2

Description

Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled by the Edge Just-In-Time (JIT) compiler, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11863 and CVE-2017-11872.

Common Vulnerability Scoring System (CVSS)

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
High
Attack complexity
Network
Attack vector
None
Availability
None
Confidentiality
Low
Integrity
None
Privileges required
Unchanged
Scope
Required
User interaction
3.1
Base score
1.6
1.4
Exploitability score
Impact score
 

Verification logic

AND
OR
vendor=microsoft AND product=edge AND version=-
vendor=microsoft AND product=chakracore AND version=-
OR
vendor=microsoft AND product=windows_10 AND version=1703
vendor=microsoft AND product=windows_10 AND version=1709
vendor=microsoft AND product=windows_server AND version=1709
 

Reference

 


Keywords

NVD

 

CVE-2017-11874

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.