104641vdb entry
http://www.securityfocus.com/bid/104641 CVE-2018-8279
HIGH
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
Record summary
CVE-2018-8279 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ChakraCoreBrowse Microsoft / ChakraCore | CVE List | ChakraCore | affected |
Microsoft EdgeBrowse Microsoft / Microsoft Edge | CVE List | Windows 10 Version 1703 for 32-bit Systems | affected |
| Windows 10 Version 1703 for x64-based Systems | affected | ||
| Windows 10 Version 1709 for 32-bit Systems | affected | ||
| Windows 10 Version 1709 for x64-based Systems | affected | ||
| Windows 10 Version 1803 for 32-bit Systems | affected | ||
| Windows 10 Version 1803 for x64-based Systems | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Edge Chakra JIT - Parameter Scope Parsing Type ConfusionExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51041256vdb entry
http://www.securitytracker.com/id/1041256 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-8279 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8279 45214exploit
https://www.exploit-db.com/exploits/45214