CVE-2018-8355

Scores

EPSS

0.796medium79.6%
0%20%40%60%80%100%

Percentile: 79.6%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Description

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka “Scripting Engine Memory Corruption Vulnerability.” This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8353, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

msrcnvd

CWEs

CWE-787

Exploits

Exploit ID: 45432

Source: exploitdb

URL: https://www.exploit-db.com/exploits/45432

Vulnerable Software (80)

Type: Configuration

Vendor: *

Product: chakracore

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:*",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

Type: Configuration

Vendor: *

Product: edge

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"    }, ...

Source: nvd

Type: Configuration

Vendor: *

Product: internet_explorer

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4343898

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4343205

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.001

Operating System: Windows 1 build 1

Identifier: KB5046630

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10.0.0.0

Operating System: Windows 0 build 0

Identifier: KB5029243

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4524135

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4519974

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4516046

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.1.0.0

Operating System: Windows 0 build 0

Identifier: KB5022835

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4561603

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4565479

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.001

Operating System: Windows 1 build 1

Identifier: KB5032191

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.000

Operating System: Windows 1 build 0

Identifier: KB5053593

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4480965

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4511872

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 1.001

Operating System: Windows 1 build 1

Identifier: KB5040426

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4486474

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4534251

Source: msrc