CVE-2018-0934 is a remote code execution vulnerability affecting ChakraCore and various versions of Microsoft Windows 10 and Windows Server 2016. It stems from how the Chakra scripting engine handles objects in memory, leading to memory corruption. This vulnerability carries a CVSS score of 7.5 (High), indicating a high potential impact on confidentiality, integrity, and availability. Exploitation requires user interaction (UI:R) and has high attack complexity (AC:H), but can be initiated remotely (AV:N). While not listed on CISA's KEV catalog, exploit code is publicly available on ExploitDB, suggesting potential for exploitation. The vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
< 1.8.2CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.