Description
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8734, CVE-2017-8751, and CVE-2017-11766.
In plain language
AI Worth attentionCVE-2017-8731 is a Microsoft Edge flaw that can let an attacker run unauthorized code on your Windows PC if a user opens a specially crafted webpage; most small businesses don’t face it by default, but you should check and patch affected Windows 10 1607 or Windows Server 2016 Edge installs.
CVE-2017-8731 is a memory corruption vulnerability in Microsoft Edge that can be triggered through a malicious website to achieve unauthorized code execution in the context of the currently logged-in user, without prior authentication (user interaction required).
What to do now
- Confirm whether your systems run Windows 10 version 1607 or Windows Server 2016 and have Microsoft Edge installed.
- For affected systems, check whether they include the Microsoft security update for CVE-2017-8731 from Microsoft’s advisory.
- Apply the Microsoft Edge/Windows update(s) referenced in the CVE-2017-8731 advisory, then restart and re-verify the update is installed.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-8731 and every CVE in our database. Create a free account — no credit card required.
Create Free Account