CVE-2017-0238: Microsoft Edge

High severity, CVSS 7.5. EPSS: 18.1% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0236.

Affected products

  • Microsoft Edge: any version
  • Microsoft Internet Explorer: version 9 only; version 10 only; version 11 only

Published 2017-05-12. Last modified 2026-06-17.