CVE-2018-0946 describes a remote code execution vulnerability in the scripting engine of Microsoft Edge and ChakraCore, stemming from how these products handle objects in memory. This "Scripting Engine Memory Corruption Vulnerability" could allow an attacker to execute arbitrary code. The vulnerability carries a high CVSS score of 7.5, indicating a significant risk. Exploitation requires user interaction (UI:R) and has high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), though the attack complexity is also high (AC:H). While not listed on the CISA KEV catalog, an exploit (EDB-44758) for a cross-context use-after-free in Microsoft Edge Chakra exists on ExploitDB. The vulnerability has received some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
<= 1.8.3CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.