CVE-2018-8291: High severity Microsoft Internet Explorer vulnerability
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.ChakraCoreto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8291?
CVE-2018-8291 has a high severity rating of 7.6.
How does CVE-2018-8291 affect my system?
CVE-2018-8291 can lead to remote code execution on systems running vulnerable versions of Microsoft browsers.
Which software is affected by CVE-2018-8291?
CVE-2018-8291 affects Microsoft Internet Explorer, Microsoft Edge, and Microsoft ChakraCore.
How do I fix CVE-2018-8291?
To fix CVE-2018-8291, users should update their Microsoft browsers and ChakraCore to the latest versions provided by Microsoft.
What is the nature of the vulnerability in CVE-2018-8291?
CVE-2018-8291 is a memory corruption vulnerability in the scripting engine of Microsoft browsers.