← back
CVE-2017-11874

CVE-2017-11874

EPSS 4.0%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 4.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled by the Edge Just-In-Time (JIT) compiler, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11863 and CVE-2017-11872.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →