CVE-2018-8288: High severity Microsoft Internet Explorer vulnerability
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.ChakraCoreto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8288?
CVE-2018-8288 has a severity rating of high, with a score of 7.6.
How do I fix CVE-2018-8288?
To address CVE-2018-8288, apply the latest security updates from Microsoft for Internet Explorer 11 and Microsoft Edge.
What software is affected by CVE-2018-8288?
CVE-2018-8288 affects Microsoft Internet Explorer, Microsoft Edge, and Microsoft ChakraCore.
What type of vulnerability is CVE-2018-8288?
CVE-2018-8288 is classified as a remote code execution vulnerability due to memory corruption in the scripting engine.
Can CVE-2018-8288 be exploited without user interaction?
Exploitation of CVE-2018-8288 typically requires user interaction, as it involves malicious web content.