CVE-2018-8456 is a remote code execution vulnerability in the ChakraCore scripting engine, affecting Microsoft Edge, ChakraCore, and Windows 10. This memory corruption flaw allows an attacker to execute arbitrary code. With a CVSS score of 7.5 (High), exploitation requires user interaction and has high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was addressed in a Microsoft Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10.1CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.