CVE-2018-0836 describes a remote code execution vulnerability in Microsoft Edge and ChakraCore on Windows 10 versions 1703 and 1709, stemming from how the scripting engine handles memory objects. This high-severity vulnerability (CVSS 7.5) requires user interaction and a high attack complexity, but successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or Metasploit modules are available, the vulnerability has garnered some community discussion and media coverage, though it is not currently on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.