First published: Fri Aug 11 2017(Updated: )
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.6.1 | 1.6.1 |
Microsoft Chakra | <=1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8658 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2017-8658, update to the latest version of Microsoft ChakraCore that addresses this vulnerability.
CVE-2017-8658 affects systems running versions of Microsoft ChakraCore up to 1.7.0.
Yes, CVE-2017-8658 can be exploited remotely, allowing an attacker to execute arbitrary code.
The potential impacts of CVE-2017-8658 include unauthorized access, data breaches, and system compromise.