{
    "id": "CVE-2018-8319",
    "published": "2018-07-11 00:29:02",
    "last_modified": "2026-06-17 02:04:37",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-682",
    "description": "A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka \"MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability.\" This affects Microsoft Research JavaScript Cryptography Library.",
    "epss_score": "0.07504",
    "epss_percentile": "0.94317",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-05 18:17:19",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "research_javascript_cryptography_library"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.securityfocus.com/bid/104655",
        "http://www.securitytracker.com/id/1041268",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8319",
        "http://www.securityfocus.com/bid/104655",
        "http://www.securitytracker.com/id/1041268",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8319"
    ]
}