Back

CVE-2017-0028

CRITICAL

A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."

Published: Jul 17, 2017 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
microsoft edge *

GitHub Security Advisory GHSA-9x82-r65p-wm47

A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 18.94%

Top 3% most likely to be exploited

Threat Score 44.9 / 100

Data Sources

NVD EPSS GitHub