Description
Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability".
In plain language
AI Worth attentionIf you run Internet Explorer on Windows 8.1/Windows RT 8.1 or Windows Server 2012 R2, there’s a high-risk way for a specially made webpage or file to trick Internet Explorer into running code as your current user—small businesses should patch if they still use Internet Explorer.
CVE-2017-8594 is a memory corruption vulnerability in Internet Explorer on Windows 8.1/Windows RT 8.1 and Windows Server 2012 R2 that can lead to arbitrary code execution in the context of the current user, typically triggered by improper handling of objects in memory when processing attacker-controlled content; a public exploit exists, but there’s no confirmed KEV listing.
What to do now
- Confirm whether your business uses Internet Explorer on Windows 8.1/Windows RT 8.1 or Windows Server 2012 R2 systems.
- For each affected system, check for installed Microsoft security updates related to CVE-2017-8594 (via Windows Update history or your patch management records).
- Install the Microsoft remediation update for CVE-2017-8594 using Microsoft’s advisory guidance.
- If you cannot patch immediately, disable or block Internet Explorer usage for users (browser alternatives, restricted shortcuts, and web/content controls), and prevent users from opening untrusted links/files in that browser until patched.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-8594 and every CVE in our database. Create a free account — no credit card required.
Create Free Account