Description
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8751, and CVE-2017-11766.
In plain language
AI Worth attentionCVE-2017-8734 is a Microsoft Edge bug in certain Windows 10/Windows Server versions that can let an attacker run code on your PC when you open a specially crafted page—so it’s a real concern if you’re using the affected Edge versions and browse untrusted sites.
CVE-2017-8734 is a network-delivered remote code execution vulnerability in Microsoft Edge on affected Windows 10 (Gold, 1511, 1607, 1703) and Windows Server 2016; a maliciously crafted input causes a memory-access error that can be triggered by user interaction (opening a crafted page), executing code in the context of the current user without requiring authentication.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-8734 and every CVE in our database. Create a free account — no credit card required.
Create Free Account