CVE-2018-8279
HIGHMicrosoft Edge and ChakraCore - Remote Code Execution via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8279. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a type confusion vulnerability in Chakra (CVE-2018-8279) by generating incorrect bytecode due to improper handling of async functions and try-catch blocks. The exploit triggers a yield operation within a try-catch, leading to type confusion in the InterpreterStackFrame::OP_ResumeYield method.
Description
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.
Exploits (1)
This PoC exploits a type confusion vulnerability in Chakra (CVE-2018-8279) by generating incorrect bytecode due to improper handling of async functions and try-catch blocks. The exploit triggers a yield operation within a try-catch, leading to type confusion in the InterpreterStackFrame::OP_ResumeYield method.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H