Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2017-11905 : What You Need to Know

Learn about CVE-2017-11905, a critical vulnerability in ChakraCore and Microsoft Edge allowing remote code execution in Windows 10 and Windows Server 2016. Find mitigation steps here.

CVE-2017-11905, also known as the "Scripting Engine Memory Corruption Vulnerability," affects ChakraCore and Microsoft Edge in various versions of Windows 10 and Windows Server 2016. This vulnerability allows unauthorized users to execute arbitrary code within the current user's context.

Understanding CVE-2017-11905

This CVE ID pertains to a critical security issue in ChakraCore and Microsoft Edge that enables remote code execution.

What is CVE-2017-11905?

The vulnerability in ChakraCore and Microsoft Edge in Windows 10 and Windows Server 2016 allows attackers to run arbitrary code within the user's context due to memory handling by the scripting engine.

The Impact of CVE-2017-11905

        Unauthorized users can execute malicious code within the current user's context.
        This vulnerability poses a significant security risk to affected systems.

Technical Details of CVE-2017-11905

This section provides detailed technical information about the vulnerability.

Vulnerability Description

The flaw in ChakraCore and Microsoft Edge allows attackers to exploit memory handling to execute arbitrary code.

Affected Systems and Versions

        Products: ChakraCore, Microsoft Edge
        Vendor: Microsoft Corporation
        Versions: Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016

Exploitation Mechanism

Attackers can exploit this vulnerability by crafting a malicious script and tricking a user into visiting a compromised website or opening a malicious file.

Mitigation and Prevention

Protecting systems from CVE-2017-11905 requires immediate action and long-term security practices.

Immediate Steps to Take

        Apply security patches provided by Microsoft promptly.
        Consider implementing security measures to prevent unauthorized code execution.

Long-Term Security Practices

        Regularly update software and systems to mitigate potential vulnerabilities.
        Educate users about safe browsing habits and the risks of opening unknown files.

Patching and Updates

        Stay informed about security updates from Microsoft and apply them as soon as they are available.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now