First published: Wed Mar 14 2018(Updated: )
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows Server 2016 | ||
Microsoft ChakraCore | <1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0933 can allow an attacker to execute arbitrary code on the victim's system via a malicious web page.
To mitigate CVE-2018-0933, ensure that your Microsoft Edge browser and Windows operating system are updated to the latest security patches.
Yes, CVE-2018-0933 affects Microsoft Edge and the Chakra scripting engine on various versions of Windows 10 and Windows Server 2016.
CVE-2018-0933 is a memory corruption vulnerability in the Chakra scripting engine that can lead to remote code execution.
Users of Microsoft Edge with vulnerable versions of Windows 10 and Windows Server 2016 are at risk from CVE-2018-0933.