Description
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, and CVE-2017-11930.
In plain language
AI Worth attentionCVE-2017-11918 is a Windows browser/scripting bug (ChakraCore, Microsoft Edge) that can let an attacker run code using your current user’s permissions; small businesses should fix it if their PCs/servers run Edge on the affected Windows versions.
CVE-2017-11918 is a scripting engine memory corruption issue in ChakraCore/ Microsoft Edge that can allow an attacker (via crafted input in Edge) to execute code with the same rights as the logged-in user.
What to do now
- Check your Windows version and whether Microsoft Edge uses ChakraCore on those machines (Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016).
- Determine your ChakraCore version in that environment.
- Upgrade ChakraCore to a fixed release: upgrade to ChakraCore 1.7.5 (fixed version).
- If you can’t upgrade right away, apply the vendor security update associated with CVE-2017-11918 and then re-check that the installed components match the fixed status.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-11918 and every CVE in our database. Create a free account — no credit card required.
Create Free Account