CVE Tools

CVE-2017-8594

Published: Jul 11, 2017Updated: May 13, 2026 Sources: CVE List NVD BDUCWE-119

Description

Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability".

In plain language

AI Worth attention

If you run Internet Explorer on Windows 8.1/Windows RT 8.1 or Windows Server 2012 R2, there’s a high-risk way for a specially made webpage or file to trick Internet Explorer into running code as your current user—small businesses should patch if they still use Internet Explorer.

Executive summary

CVE-2017-8594 is a memory corruption vulnerability in Internet Explorer on Windows 8.1/Windows RT 8.1 and Windows Server 2012 R2 that can lead to arbitrary code execution in the context of the current user, typically triggered by improper handling of objects in memory when processing attacker-controlled content; a public exploit exists, but there’s no confirmed KEV listing.

If affected, business impact
Account and session takeoverMalware execution on devicesData theft from user contextBusiness disruption via compromise

What to do now

  1. Confirm whether your business uses Internet Explorer on Windows 8.1/Windows RT 8.1 or Windows Server 2012 R2 systems.
  2. For each affected system, check for installed Microsoft security updates related to CVE-2017-8594 (via Windows Update history or your patch management records).
  3. Install the Microsoft remediation update for CVE-2017-8594 using Microsoft’s advisory guidance.
  4. If you cannot patch immediately, disable or block Internet Explorer usage for users (browser alternatives, restricted shortcuts, and web/content controls), and prevent users from opening untrusted links/files in that browser until patched.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:HPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 1 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-8594 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows