CVE-2018-0937 is a remote code execution vulnerability in ChakraCore and Microsoft Windows 10 versions 1703 and 1709, stemming from how the Chakra scripting engine handles objects in memory. This high-severity vulnerability (CVSS 7.5) can be exploited with high complexity via a network attack requiring user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code exists in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog, its FAUCET Risk Score of 92/100 and EPSS percentile suggest a significant threat. The vulnerability received limited media coverage and community discussion, indicating it may not have been widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.