First published: Wed Jan 10 2018(Updated: )
Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ChakraCore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0818 is rated as important due to its potential to allow arbitrary code execution.
To fix CVE-2018-0818, update to the latest version of Microsoft ChakraCore that addresses this vulnerability.
CVE-2018-0818 affects systems running the Microsoft ChakraCore scripting engine.
The impact of CVE-2018-0818 can lead to a bypass of Control Flow Guard, enabling arbitrary code execution on the target system.
CVE-2018-0818 exploits the way ChakraCore handles memory access, allowing attackers to trigger a bypass of security measures.