CVE-2018-0873 is a memory corruption vulnerability in the Chakra scripting engine affecting Microsoft Edge and various versions of Windows 10 and Windows Server 2016. This flaw allows for remote code execution due to how the engine handles objects in memory. With a CVSS score of 7.5 (High), exploitation requires user interaction (UI:R) and has high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), though with high attack complexity (AC:H). While it has a high FAUCET Risk Score of 92/100 and some community discussion/media coverage, there is no known active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.