CVE-2018-8298
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- ChakraCore Scripting Engine Type Confusion Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 75% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-843
מוצרים מושפעים
microsoft: chakracore
קישורים
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8298 PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8298 PatchVendor Advisory
- https://www.exploit-db.com/exploits/45217/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45217/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/104639 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/104639 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource