cbcvebase.
CVE-2018-8139
published 2018-05-09

CVE-2018-8139: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory…

PriorityP267high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
66.55%
99.2th percentile
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftchakracore<= 1.8.3
microsoftchakracore
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcchakracore
msrcmicrosoft_edge_on_windows_10_version_1803_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1803_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via a specially crafted website targeting Microsoft Edge (HTML-based) scripting engine; monitor for exploitation of BoundFunction::NewInstance OOB read via Reflect.construct on a bound function with new.target access
  • PoC exploit pattern: use of Reflect.construct() on a bound function combined with new.target property access inside the called function — flag JavaScript matching this pattern in Edge/ChakraCore contexts
  • Web-based attack vector: attacker hosts or compromises a website to serve malicious content; monitor for drive-by download scenarios targeting Microsoft Edge users, including sites hosting user-provided content or advertisements
  • ·Exploit status at time of advisory: publicly disclosed but not yet observed exploited in the wild; exploitation assessed as 'More Likely' for latest software release
  • ·Affected component is Microsoft Edge (HTML-based) ChakraCore scripting engine; patch available in ChakraCore v1.8.4 and KB4103721

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
vendor_msrc4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.