CVE-2017-0208Sensitive Information Exposure in Corporation Edge

Severity
4.3MEDIUMNVD
EPSS
14.9%
top 5.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12
Latest updateMay 17

Description

An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
OSV
ChakraCore information disclosure vulnerability2022-05-17
GHSA
ChakraCore information disclosure vulnerability2022-05-17
CVEList
CVE-2017-0208: An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory2017-04-12

📋Vendor Advisories

1
Microsoft
Scripting Engine Information Disclosure Vulnerability2017-04-11
CVE-2017-0208 — Sensitive Information Exposure | cvebase