CVE-2017-8644
MEDIUMMicrosoft Edge - Information Disclosure via Memory Object Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-8644. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits an out-of-bounds memory access vulnerability in Microsoft Edge's handling of datetime input elements, leading to a potential write primitive. The issue arises from an uninitialized index causing an invalid array access in CInputDateTimeScrollerElement::_SelectValueInternal.
Description
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.
Exploits (1)
This PoC exploits an out-of-bounds memory access vulnerability in Microsoft Edge's handling of datetime input elements, leading to a potential write primitive. The issue arises from an uninitialized index causing an invalid array access in CInputDateTimeScrollerElement::_SelectValueInternal.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N