Executive brief
Microsoft JScript, a core scripting engine used in Windows and various Microsoft applications, contains a flaw in how it converts between numeric data types. An attacker can exploit this vulnerability over the network to execute arbitrary code on affected systems, potentially compromising data, installing malware, or taking control of the machine.
Technical details
The vulnerability stems from incorrect handling of numeric type conversions in Microsoft JScript. The flaw allows an attacker to trigger arbitrary code execution through network-based attack vectors without requiring authentication. The attack vector is network-accessible, meaning remote exploitation is possible. Microsoft has released security updates to correct the type conversion logic and prevent exploitation.
Affected products
- Microsoft JScript
Timeline
- 2026-09-08: disclosed