Vulnerability · NVD
CVE-2017-0152
CVE-2017-0152, high severity (CVSS 8.1): 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 8.1
- Exploitation
- 10.8 %
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| microsoft |
edge All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |