CVE-2018-8500: Critical severity microsoft chakra vulnerability
Published Oct 10, 2018
·Updated
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.
Affected Software
2 affected componentsFixes available
nuget/Microsoft.ChakraCore<1.11.2
1.11.2
Microsoft ChakraCore
Remediation
Event History
Oct 10, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
May 13, 2022
Advisory Published
01:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-8500?
CVE-2018-8500 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2018-8500?
To mitigate CVE-2018-8500, upgrade ChakraCore to version 1.11.2.
3
What software is affected by CVE-2018-8500?
CVE-2018-8500 affects Microsoft ChakraCore versions prior to 1.11.2.
4
What type of vulnerability is CVE-2018-8500?
CVE-2018-8500 is categorized as a remote code execution vulnerability.
5
Is there a patch available for CVE-2018-8500?
Yes, the patch for CVE-2018-8500 is included in ChakraCore version 1.11.2.