Description
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.
In plain language
AI Worth attentionCVE-2017-8751 is a Microsoft Edge bug in Windows 1703 that can let an attacker run code on your PC if a user opens a specially crafted page or file; most small businesses should act by updating Edge/Windows promptly.
CVE-2017-8751 is a Microsoft Edge memory corruption issue (CWE-119) in Windows 1703 that can enable arbitrary code execution in the current user context, typically triggered through crafted content that requires user interaction.
What to do now
- Check whether you run Windows 1703 and use Microsoft Edge on that device.
- On affected machines, update Microsoft Edge and Windows using Microsoft’s remediation guidance for CVE-2017-8751.
- If you can’t update immediately, limit users from opening unknown links/attachments in Edge until updates are applied.
- After updating, confirm the system is no longer on the Windows 1703 Edge configuration described in the Microsoft advisory for CVE-2017-8751.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-8751 and every CVE in our database. Create a free account — no credit card required.
Create Free Account