CVE-2018-0778 is a critical memory corruption vulnerability in the Microsoft Edge scripting engine, affecting Windows 10 version 1709 and ChakraCore. This flaw allows an unauthenticated attacker to execute arbitrary code in the context of the current user, typically through a malicious website. With a CVSS score of 7.5 (HIGH), exploitation requires user interaction (e.g., visiting a crafted page) and has high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its EPSS score and media coverage indicate significant potential risk, though no public exploit code or active exploitation has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.