CVE-2018-0893 is a remote code execution vulnerability in Microsoft Edge across various Windows 10 and Server 2016 versions, stemming from how the scripting engine handles objects in memory. With a CVSS score of 7.5 (High), successful exploitation requires user interaction and could lead to complete compromise of confidentiality, integrity, and availability. While it has a high FAUCET Risk Score and notable community discussion and media coverage, there is currently no public exploit code available, nor is it listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.