First published: Wed Aug 15 2018(Updated: )
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8381, CVE-2018-8384.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.10.2 | 1.10.2 |
Microsoft Chakra | <=1.10.1 | |
Microsoft Edge Beta | ||
Microsoft Windows 10 | =1803 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8380 is classified as a critical remote code execution vulnerability.
To address CVE-2018-8380, users should apply the latest security patches provided by Microsoft for Edge and ChakraCore.
CVE-2018-8380 affects Microsoft Edge and ChakraCore versions up to 1.10.1.
Successful exploitation of CVE-2018-8380 allows an attacker to execute arbitrary code on the affected system.
Currently, there are no known workarounds for CVE-2018-8380 other than applying available security updates.