← Back

CVE-2017-8606

nvd nist
Published: Jul 11, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8596, CVE-2017-8618, CVE-2017-8619, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8595, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609

Affected (4)

2 products
Edge
Internet Explorer
Configuration A
4 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
All versions
Microsoft
Version 10
Version 11
Version 9
Running on/withPlatform Versions
Microsoft
Windows 10
All versions
Microsoft
Windows 10
Version 1511
Microsoft
Windows 10
Version 1607
Microsoft
Windows 10
Version 1703
Microsoft
Windows 7
All versions
Microsoft
Windows 8.1
All versions
Microsoft
Windows Rt 8.1
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
Version r2 sp1
Microsoft
Windows Server 2012
All versions
Microsoft
Windows Server 2012
Version r2
Microsoft
Windows Server 2016
All versions

References (8)

Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.