cbcvebase.
CVE-2018-8275
published 2018-07-11

CVE-2018-8275: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability."…

PriorityP274high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
19.23%
97.0th percentile
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8279, CVE-2018-8301.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftchakracore<= 1.10.0
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcchakracore
msrcmicrosoft_edge_on_windows_10_version_1607_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1607_for_x64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1703_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1703_for_x64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1709_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1709_for_x64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1803_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1803_for_x64-based_systems
msrcmicrosoft_edge_on_windows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in the Microsoft Scripting Engine (ChakraCore) as used by Microsoft Edge; monitor for Edge renderer process memory corruption or unexpected child process spawning from Microsoft Edge.
  • Attack vector is web-based; monitor for users being directed to attacker-controlled or compromised websites via email/IM lures, particularly links opened in Microsoft Edge.
  • Social engineering delivery via email or Instant Messenger attachments/links is the primary initial access vector; monitor for Edge being launched from email clients or IM applications.
  • ·Exploit status at time of advisory was 'Exploitation More Likely' for the latest software release, but no public exploit or active exploitation was confirmed.
  • ·The fix is delivered via ChakraCore v1.10.1 and multiple Windows cumulative update KBs; ensure patching targets all affected OS versions.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.