Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-0818

Опубликовано: 03 янв. 2018
Источник: msrc
CVSS3: 4.3
EPSS Средний

Описание

Scripting Engine Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed. By itself, the CFG bypass vulnerability does not allow arbitrary code execution. However, an attacker could use the CFG bypass vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code on a target system.

To exploit the CFG bypass vulnerability, a user must be logged on to the Microsoft Chakra scripting engine and running it. The user would then need to browse to a malicious website.

The security update addresses the CFG bypass vulnerability by helping to ensure that the Microsoft Chakra scripting engine properly handles accessing memory.

Обновления

ПродуктСтатьяОбновление
ChakraCore

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

Older Software Release

Exploitation Unlikely

EPSS

Процентиль: 94%
0.15373
Средний

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".

CVSS3: 7.5
github
около 3 лет назад

ChakraCore RCE Vulnerability

EPSS

Процентиль: 94%
0.15373
Средний

4.3 Medium

CVSS3