CVE-2018-8355
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 68%
from disclosure to weapon34 days
Published on NVDAug 15
1st PoC+34d
exploitation probability
68%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8353, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.
public PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45432cve_referencewww.exploit-db.com/exploits/45432/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.