← back
CVE-2024-38178

Scripting Engine Memory Corruption Vulnerability

CVSS 7.5 HIGHEPSS 39.5%● KEVCWE-843
In short

A flaw in the scripting engine allows attackers to corrupt memory through specially crafted scripts, potentially causing crashes or unauthorized code execution. This vulnerability affects systems that process untrusted script content.

Technical detail

Type confusion vulnerability (CWE-843) in the scripting engine allows memory corruption via malformed script objects. Remote attackers can exploit this by sending crafted scripts that bypass type checking, leading to arbitrary memory write and potential code execution with the privileges of the affected process.

Summary generated and translated by AI from the official description.
Scripting Engine Memory Corruption Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →