CVE-2018-0933: vulnerability in Microsoft Corporation ChakraCore, Microsoft Edge
Published · Updated
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 66%
from disclosure to weapon20 days
Published on NVDMar 14
1st PoC+20d
exploitation probability
66%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
Affected products
Microsoft Corporation · ChakraCore, Microsoft Edgepublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44396cve_referencewww.exploit-db.com/exploits/44396/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Microsoft Corporation ChakraCore, Microsoft Edge
In the same product, most dangerous first.