Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-8353. PoCs published by Google Security Research, whereisr0da.
AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2018-8353, a use-after-free vulnerability in jscript.dll related to the lastIndex property of a RegExp object. The exploit demonstrates memory corruption in Internet Explorer by triggering garbage collection and reallocating freed memory blocks.
Description
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.
Exploits (2)
This is a proof-of-concept exploit for CVE-2018-8353, a use-after-free vulnerability in jscript.dll related to the lastIndex property of a RegExp object. The exploit demonstrates memory corruption in Internet Explorer by triggering garbage collection and reallocating freed memory blocks.
This repository contains a README referencing a Proof of Concept (PoC) for CVE-2018-8353, a Use After Free vulnerability in the Microsoft Scripting Engine. It points to a Chromium Project Zero issue but does not include actual exploit code.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H