Описание
ChakraCore RCE Vulnerability
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka Chakra Scripting Engine Memory Corruption Vulnerability. This CVE ID is unique from CVE-2020-0811.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-0812
- https://github.com/chakra-core/ChakraCore/pull/6385
- https://github.com/chakra-core/ChakraCore/pull/6385/commits/bdd48f21a93bd9dc7dd5f783b58df8bef72583c4
- https://github.com/chakra-core/ChakraCore
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0812
Пакеты
Наименование
Microsoft.ChakraCore
nuget
Затронутые версииВерсия исправления
< 1.11.17
1.11.17
Связанные уязвимости
CVSS3: 7.5
nvd
почти 6 лет назад
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811.
CVSS3: 4.2
fstec
почти 6 лет назад
Уязвимость обработчика JavaScript-сценариев ChakraCore браузера Microsoft Edge позволяющая нарушителю выполнить произвольный код в контексте текущего пользователя