CVE-2018-0768 is a scripting engine memory corruption vulnerability affecting Microsoft Edge in Windows 10 version 1709, allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a network-based attack requiring user interaction and high impacts to confidentiality, integrity, and availability. While the vulnerability was addressed in a January 2018 Patch Tuesday update, there is no public exploit code available, and it is not listed in CISA's KEV catalog. Despite limited community discussion and media coverage, its EPSS score suggests a higher than average probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.