CVE-2018-0780 is an information disclosure vulnerability in Microsoft Edge across various Windows 10 and Server 2016 versions, stemming from how its scripting engine handles memory objects. This medium-severity vulnerability (CVSS 5.3) can be exploited remotely with high attack complexity, requiring user interaction, to disclose sensitive information that could aid further system compromise. While not listed in CISA's KEV catalog, an out-of-bounds read exploit for Microsoft Edge Chakra exists on ExploitDB, and the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.