Executive brief
A type confusion vulnerability exists in the ChakraCore scripting engine due to the way it handles objects in memory. An attacker could exploit this to execute arbitrary code remotely, typically requiring user interaction such as visiting a malicious website.
Affected products
- Microsoft ChakraCore up to (excluding) 1.10.1
Timeline
- 2018-07-10: disclosed: NVD Published Date
- 2018-07-10: patched: Microsoft released security guidance and patches.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-03: exploited: Confirmed as exploited in the wild per CISA KEV.