Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2017-8636

CVE-2017-8636, high severity (CVSS 7.5): 1 tracked app concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
7.5

NVD scale

Exploitation
72.1 %

EPSS, predicted over 30 days

Tracked apps
1
Still exposed
0
Public exploit : ExploitDB

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 72.12% exploit likely percentile 99.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 9 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (1)
Vendor Product Versions
microsoft edge
All platforms (wildcard)
-
View on NVD ↗ Advisory · portal.msrc.microsoft.com