CVE-2017-8659Sensitive Information Exposure in Corporation Microsoft Scripting Engine

Severity
4.3MEDIUMNVD
EPSS
14.6%
top 5.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 17

Description

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5microsoft_corporation/microsoft_scripting_engineMicrosoft Windows 10 1703.

Patches

🔴Vulnerability Details

3
GHSA
ChakraCore information disclosure vulnerability2022-05-17
OSV
ChakraCore information disclosure vulnerability2022-05-17
CVEList
CVE-2017-8659: Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripti2017-08-08

📋Vendor Advisories

1
Microsoft
Scripting Engine Information Disclosure Vulnerability2017-08-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - August 20172017-08-08
Talos
Microsoft Patch Tuesday - August 20172017-08-08
CVE-2017-8659 — Sensitive Information Exposure | cvebase