CVE-2018-0773 is a scripting engine memory corruption vulnerability in Microsoft Edge on Windows 10 1709, allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with high complexity, requiring user interaction, and leading to high impact on confidentiality, integrity, and availability. While the EPSS score suggests a moderate likelihood of exploitation compared to other CVEs, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion. It was addressed as part of Microsoft's January Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.