CVE-2018-8359 describes a remote code execution vulnerability within the ChakraCore scripting engine, specifically related to how it handles objects in memory. This flaw affects Microsoft ChakraCore, allowing an attacker to execute arbitrary code. With a CVSS score of 7.5 (High), exploitation requires user interaction (UI:R) and has high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), but with high attack complexity (AC:H). While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has received some community discussion and media coverage, though it is not currently on the CISA KEV catalog or considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.