← back
CVE-2018-8291

CVE-2018-8291

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 70%
from disclosure to weapon37 days
Published on NVDJul 11
1st PoC+37d
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.