CVE-2017-8659
Status: ModifiedMedium (4.3)—
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability".
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 6.00%
- Percentile among all scored CVEs: 93
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://www.securityfocus.com/bid/100029
- http://www.securitytracker.com/id/1039095
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8659
- http://www.securityfocus.com/bid/100029
- http://www.securitytracker.com/id/1039095
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8659
Raw JSON (NVD)
Show
{
"id": "CVE-2017-8659",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "Microsoft Corporation",
"product": "Microsoft Scripting Engine",
"versions": [
{
"status": "affected",
"version": "Microsoft Windows 10 1703."
}
]
}
]
}
],
"published": "2017-08-08T21:29:01.610",
"references": [
{
"url": "http://www.securityfocus.com/bid/100029",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id/1039095",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@microsoft.com"
},
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8659",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/100029",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1039095",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8659",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka \"Scripting Engine Information Disclosure Vulnerability\"."
},
{
"lang": "es",
"value": "Microsoft Edge en Microsoft Windows 10 1703 permite que un atacante obtenga información para compromete aún más la seguridad del sistema del usuario debido a que el motor de scripting Chakra no gestiona correctamente los objetos en la memoria. Esto también se conoce como \"Scripting Engine Information Disclosure Vulnerability\"."
}
],
"lastModified": "2026-06-17T01:26:44.813",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BD5B232-95EA-4F8E-8C7D-7976877AD243"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AEE2E768-0F45-46E1-B6D7-087917109D98"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secure@microsoft.com"
}