CVE-2018-8139 is a remote code execution vulnerability in the scripting engine of Microsoft Edge and ChakraCore, stemming from how these products handle objects in memory. This high-severity flaw (CVSS 7.5) can be exploited by an unauthenticated attacker over a network, though it requires user interaction and has high attack complexity. Successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, there is public exploit code available (EDB-45012) and it has received some community and media attention, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
<= 1.8.3CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.