CVE-2017-8659

MEDIUM

Microsoft Edge < 1.6.1 - Information Disclosure

Title source: rule

Description

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability".

Scores

CVSS v3 4.3
EPSS 0.1283
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
microsoft/edge
nuget/Microsoft.ChakraCore < 1.6.1NuGet
Microsoft Corporation/Microsoft Scripting Engine < Microsoft Windows 10 1703.
Published Aug 08, 2017
Tracked Since Feb 18, 2026