First published: Mon May 15 2017(Updated: )
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.4.4 | 1.4.4 |
Microsoft Edge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0223 has a high severity rating due to its potential for remote code execution.
To fix CVE-2017-0223, update Microsoft ChakraCore to version 1.4.4 or later.
CVE-2017-0223 affects Microsoft ChakraCore and Microsoft Edge browsers.
Yes, CVE-2017-0223 is unique and distinct from CVE-2017-0252.
CVE-2017-0223 is classified as a scripting engine memory corruption vulnerability.