CVE-2018-0953
HIGH EXPLOITED IN THE WILDMicrosoft Edge and ChakraCore - Remote Code Execution via Scripting Engine Memory Corruption
Title source: llmExploitation Summary
CVE-2018-0953 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Google Security Research.
AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in ChakraCore's JavascriptNativeFloatArray::SetItem method. By passing a specific magic value, it forces a float array to be converted to a var array, leading to potential memory corruption.
Description
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139.
Exploits (1)
This exploit leverages a type confusion vulnerability in ChakraCore's JavascriptNativeFloatArray::SetItem method. By passing a specific magic value, it forces a float array to be converted to a var array, leading to potential memory corruption.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H