CVE-2018-0837 describes a critical scripting engine memory corruption vulnerability in Microsoft Edge and ChakraCore, impacting various versions of Windows 10 and Windows Server 2016. This flaw, specifically a type confusion issue in Chakra JIT, could allow remote code execution if a user visits a specially crafted website. Rated with a CVSS score of 7.5 (HIGH), it requires user interaction and has high impacts on confidentiality, integrity, and availability, though attack complexity is also high. While not on the CISA KEV catalog, an ExploitDB entry exists, and its high EPSS score and community discussion indicate significant attention, despite no known active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.