CVE-2018-8390 is a remote code execution vulnerability in the ChakraCore scripting engine, affecting Microsoft Edge and ChakraCore, stemming from improper handling of objects in memory. It carries a high CVSS score of 7.5, indicating a network-based attack with high complexity, requiring user interaction, but leading to high impact on confidentiality, integrity, and availability. While not actively exploited in the wild (not in KEV), there is no publicly available exploit code (Metasploit, Nuclei, ExploitDB), and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10.1CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.