CVE-2018-0936 is a remote code execution vulnerability affecting ChakraCore and Microsoft Windows 10 version 1709, stemming from memory corruption within the Chakra scripting engine. This vulnerability carries a high CVSS score of 7.5, indicating a high impact on confidentiality, integrity, and availability, with a network attack vector and high attack complexity requiring user interaction. While no public exploit code or active exploitation is reported, its high EPSS and FAUCET Risk Score suggest significant potential for impact. Community discussion and media coverage are limited, with one article mentioning its fix in a Microsoft Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.