cbcvebase.
CVE-2017-8644
published 2017-08-08

CVE-2017-8644: Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft…

PriorityP334medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EXPLOIT
EPSS
15.12%
96.6th percentile
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoft_corporationmicrosoft_edge——
msrcmicrosoft_edge_on_windows_10_for_32-bit_systems——
msrcmicrosoft_edge_on_windows_10_for_x64-based_systems——
msrcmicrosoft_edge_on_windows_10_version_1511_for_32-bit_systems——
msrcmicrosoft_edge_on_windows_10_version_1511_for_x64-based_systems——
msrcmicrosoft_edge_on_windows_10_version_1607_for_32-bit_systems——
msrcmicrosoft_edge_on_windows_10_version_1607_for_x64-based_systems——
msrcmicrosoft_edge_on_windows_10_version_1703_for_32-bit_systems——
msrcmicrosoft_edge_on_windows_10_version_1703_for_x64-based_systems——
msrcmicrosoft_edge_on_windows_server_2016——

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.