CVE-2018-8177 is a remote code execution vulnerability found in the Chakra scripting engine, specifically affecting Microsoft Edge and ChakraCore, due to improper handling of objects in memory. This vulnerability carries a high CVSS score of 7.5, indicating a significant risk where an attacker could achieve full compromise (confidentiality, integrity, availability) with high impact, though requiring user interaction and high attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community and media attention, including coverage in a BleepingComputer article regarding Microsoft's May 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
<= 1.8.3CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.