CVE-2018-0951 is a remote code execution vulnerability in Microsoft Edge, stemming from a scripting engine memory corruption flaw. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to execute arbitrary code on a user's system by enticing them to visit a specially crafted website, requiring high attack complexity. The potential impact includes complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, and with no public exploit code available on common platforms like Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.