PoC Index

CVE-2018-8298

KEVHIGH 7.6EPSS 74.8%

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H
CVSS v2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
74.79% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2022-03-03
Published
2018-07-11
Updated
2025-10-21

ExploitDB entries (1)

References

Related