First published: Thu Sep 13 2018(Updated: )
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8391, CVE-2018-8456, CVE-2018-8457, CVE-2018-8459.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.11.1 | 1.11.1 |
ChakraCore | <=1.10.1 | |
Microsoft Edge Beta | ||
Windows 10 | ||
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Windows 10 | =1803 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8354 is rated as critical due to its potential for remote code execution.
To fix CVE-2018-8354, update Microsoft Edge and ChakraCore to the latest versions provided by Microsoft.
CVE-2018-8354 affects Microsoft Edge and versions of ChakraCore up to 1.10.1 inclusive.
Yes, CVE-2018-8354 can be exploited remotely, allowing an attacker to execute arbitrary code.
There is no specific workaround for CVE-2018-8354, so applying the update is recommended to mitigate the risk.