Описание
Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.15373
Средний
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
EPSS
Процентиль: 94%
0.15373
Средний
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
NVD-CWE-noinfo