CVE-2018-8145
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 67%
from disclosure to weapon64 days
Published on NVDMay 9
1st PoC+64d
exploitation probability
67%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.
Affected products
Microsoft · ChakraCoreMicrosoft · Internet Explorer 10Microsoft · Internet Explorer 11Microsoft · Microsoft Edgepublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45011cve_referencewww.exploit-db.com/exploits/45011/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.