CVE-2017-11916

high

Description

ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11918, and CVE-2017-11930.

References

https://github.com/advisories/GHSA-735f-mx7h-46w8

https://github.com/advisories/GHSA-5f5r-65pm-r3wr

https://github.com/advisories/GHSA-923j-972p-hchf

https://github.com/advisories/GHSA-72gm-pp6q-gpx5

https://github.com/advisories/GHSA-xw5f-g937-wgm2

https://github.com/advisories/GHSA-qfcq-4vv7-9mq7

https://github.com/advisories/GHSA-9qpf-v72j-j9qh

https://github.com/advisories/GHSA-8r5c-8v97-g7vh

https://github.com/advisories/GHSA-c6r3-ghjw-hgrj

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11916

http://www.securityfocus.com/bid/102090

Details

Source: Mitre, NVD

Published: 2017-12-12

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.06172