CVE-2018-8298 is a remote code execution vulnerability in the ChakraCore scripting engine, specifically a memory corruption flaw affecting Microsoft ChakraCore. This vulnerability has a high CVSS score of 7.5, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community attention and media coverage. While no Metasploit or Nuclei exploits are publicly available, an ExploitDB entry details a type confusion exploit for Microsoft Edge Chakra JIT.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.1CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.