102399vdb entry
http://www.securityfocus.com/bid/102399 CVE-2018-0774
HIGH
Microsoft Edge Chakra - Incorrect Scope Handling
Record summary
CVE-2018-0774 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft EdgeBrowse Microsoft Corporation / Microsoft Edge | CVE List | Windows 10 1709 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Edge Chakra - Incorrect Scope HandlingExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51040100vdb entry
http://www.securitytracker.com/id/1040100 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0774 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0774 43715exploit
https://www.exploit-db.com/exploits/43715