CVE-2018-8298 KEV EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 74.5% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-17.
Description
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 74.52% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-843 |
| On CISA KEV | yes — remediate by 2022-03-17 |
| Public exploit | yes |
| Published | 2018-07-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | ChakraCore Scripting Engine Type Confusion Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-17 |
| Vendor / product | ChakraCore / ChakraCore scripting engine |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | chakracore |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion | 2018-08-17 |
References
- http://www.securityfocus.com/bid/104639
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8298
- https://www.exploit-db.com/exploits/45217/
- http://www.securityfocus.com/bid/104639
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8298
- https://www.exploit-db.com/exploits/45217/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8298
→ the Explorer · watch your stack · NVD