Junglewise Threat Intelligence

CVE-2018-8298: ChakraCore RCE Vulnerability

CVE-2018-8298 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-13

Technologies: Microsoft ChakraCore. Vendors: Microsoft, NuGet.

Executive brief

A type confusion vulnerability exists in the ChakraCore scripting engine due to the way it handles objects in memory. An attacker could exploit this to execute arbitrary code remotely, typically requiring user interaction such as visiting a malicious website.

Affected products

  • Microsoft ChakraCore up to (excluding) 1.10.1

Timeline

  • 2018-07-10: disclosed: NVD Published Date
  • 2018-07-10: patched: Microsoft released security guidance and patches.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: exploited: Confirmed as exploited in the wild per CISA KEV.

Related threats