First published: Wed Jul 11 2018(Updated: )
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.10.1 | 1.10.1 |
Microsoft Chakra | <1.10.1 | |
Microsoft ChakraCore | ||
ChakraCore | <1.10.1 | |
<1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8298 is classified as a critical remote code execution vulnerability.
To fix CVE-2018-8298, update to Microsoft ChakraCore version 1.10.1 or later.
CVE-2018-8298 is a memory corruption vulnerability in the ChakraCore scripting engine.
CVE-2018-8298 affects Microsoft ChakraCore versions prior to 1.10.1.
Yes, CVE-2018-8298 can allow an attacker to execute arbitrary code on the affected system.