Vulnerabilities > CVE-2018-8384 - Type Confusion vulnerability in Microsoft Chakracore

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
microsoft
CWE-843
exploit available

Summary

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8380, CVE-2018-8381.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Exploit-Db

descriptionMicrosoft Edge Chakra - 'PathTypeHandlerBase::SetAttributesHelper' Type Confusion. CVE-2018-8384. Dos exploit for Windows platform. Tags: Denial of Service (...
fileexploits/windows/dos/45431.js
idEDB-ID:45431
last seen2018-10-07
modified2018-09-18
platformwindows
port
published2018-09-18
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45431/
titleMicrosoft Edge Chakra - 'PathTypeHandlerBase::SetAttributesHelper' Type Confusion
typedos

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149414/GS20180918023129.txt
idPACKETSTORM:149414
last seen2018-09-18
published2018-09-18
reporterGoogle Security Research
sourcehttps://packetstormsecurity.com/files/149414/Microsoft-Edge-Chakra-PathTypeHandlerBase-SetAttributesHelper-Type-Confusion.html
titleMicrosoft Edge Chakra PathTypeHandlerBase::SetAttributesHelper Type Confusion