HTTP: Microsoft Edge CVE-2017-11888 Use After Free

This signature attempts to prevent a Use-after-Free vulnerability in Microsoft Edge. Successful exploitation of this vulnerability can achieve Remote Code Execution

Extended Description

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability".

References

CVE: CVE-2017-11888

Short Name
HTTP:STC:IE:CVE-2017-11888-UAF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
After CVE-2017-11888 CVE-2018-8125 Edge Free Microsoft Use
Release Date
12/12/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
CVSS Score

7.6

Found a potential security threat?