Microsoft Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with ChakraCore.
Products
Clear product- Microsoft Edge90 vulnerabilities
- Microsoft Windows63 vulnerabilities
- Internet Explorer46 vulnerabilities
- Microsoft Office45 vulnerabilities
- Windows kernel41 vulnerabilities
- ChakraCore, Microsoft Edge40 vulnerabilities
- Windows33 vulnerabilities
- Windows Uniscribe30 vulnerabilities
- Browser20 vulnerabilities
- Microsoft Scripting Engine18 vulnerabilities
- Microsoft SharePoint17 vulnerabilities
- Windows Hyper-V17 vulnerabilities
- Office14 vulnerabilities
- Edge13 vulnerabilities
- Equation Editor12 vulnerabilities
- Hyper-V12 vulnerabilities
- ChakraCore, Microsoft Edge, Internet Explorer10 vulnerabilities
- ASP.NET Core9 vulnerabilities
- Microsoft Edge, ChakraCore9 vulnerabilities
- ChakraCore8 vulnerabilities
- Uniscribe8 vulnerabilities
- Win32k8 vulnerabilities
- Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 20168 vulnerabilities
- Internet Explorer, Microsoft Edge7 vulnerabilities
- Malware Protection Engine7 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-0925HIGH | ChakraCore RCE VulnerabilityChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0889, CVE-2018-0893, and CVE-2018-0935. CWE-787Mar 14, 2018 | CVSS7.5v3.0 | EPSS11.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0858HIGH | ChakraCore RCE VulnerabilityChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0859, CVE-2018-0860, CVE-2018-0861, and CVE-2018-0866. CWE-787Feb 15, 2018 | CVSS7.5v3.0 | EPSS14.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0818HIGH | ChakraCore RCE VulnerabilityMicrosoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass". Jan 10, 2018 | CVSS7.5v3.0 | EPSS3.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11916HIGH | ChakraCore RCE VulnerabilityChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912,… CWE-119Dec 12, 2017 | CVSS7.5v3.0 | EPSS6.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11767CRITICAL | ChakraCore vulnerable to privilege escalationChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". CWE-119Nov 2, 2017 | CVSS9.8v3.0 | EPSS9.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11801HIGH | ChakraCore RCE VulnerabilityChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-1… CWE-200Oct 13, 2017 | CVSS7.5v3.0 | EPSS5.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11797HIGH | ChakraCore RCE VulnerabilityChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-1… CWE-200Oct 13, 2017 | CVSS7.5v3.0 | EPSS5.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-8658CRITICAL | ChakraCore RCE VulnerabilityA remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". CWE-119Aug 11, 2017 | CVSS9.8v3.0 | EPSS20.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |