CVE-2018-0776 is a critical scripting engine memory corruption vulnerability in Microsoft Edge affecting various Windows 10 and Server 2016 versions. This flaw allows an unauthenticated attacker to execute arbitrary code in the context of the current user, primarily through user interaction (e.g., visiting a malicious website). With a CVSS score of 7.5 (High) and a FAUCET Risk Score of 99/100, its high complexity and potential for complete compromise are significant concerns. While not on the CISA KEV catalog, an ExploitDB entry (EDB-43723) exists, and its high EPSS score and community discussion indicate a strong likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.