CVE-2018-0838 is a critical memory corruption vulnerability in the Microsoft Edge browser and ChakraCore scripting engine, affecting various versions of Windows 10 and Windows Server 2016. This flaw allows for remote code execution due to improper handling of objects in memory. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, successful exploitation requires user interaction (e.g., clicking a malicious link) but can lead to full compromise of the affected system. While not listed in CISA's KEV catalog, public exploit code exists (EDB-44080), and there has been notable community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.