CVE-2018-0834
HIGHChakraCore - Remote Code Execution via Memory Corruption in Scripting Engine
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-0834. PoCs published by Google Security Research, SpiralBL0CK.
AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in ChakraCore's JIT compiler by manipulating array prototypes, leading to potential arbitrary code execution. The PoC demonstrates the issue by triggering incorrect array type handling during optimization.
Description
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0858, CVE-2018-0859, CVE-2018-0860, CVE-2018-0861, and CVE-2018-0866.
Exploits (2)
This exploit leverages a type confusion vulnerability in ChakraCore's JIT compiler by manipulating array prototypes, leading to potential arbitrary code execution. The PoC demonstrates the issue by triggering incorrect array type handling during optimization.
This is a working exploit PoC for CVE-2018-0834, a memory corruption vulnerability in Microsoft ChakraCore. The exploit leverages type confusion and memory manipulation to achieve arbitrary code execution, bypassing mitigations like CFG, DEP, and ASLR.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H