cbcvebase.
CVE-2018-8279
published 2018-07-11

CVE-2018-8279: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability."…

PriorityP269high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
71.04%
99.3th percentile
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftchakracore<= 1.10.0
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcchakracore
msrcmicrosoft_edge_on_windows_10_version_1703_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1703_for_x64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1709_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1709_for_x64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1803_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1803_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • Type confusion triggered by Yield operations incorrectly generated inside a try-catch block in Chakra JIT, leading to type confusion in InterpreterStackFrame::OP_ResumeYield
  • Exploit vector is a specially crafted website delivered via Microsoft Edge; monitor for suspicious Edge navigations combined with async/class/computed-property syntax abuse in JavaScript
  • PoC trigger pattern involves an async function with a default parameter containing a class with a computed method name using 'await' — detect this JS pattern in network traffic or script analysis
  • Vulnerability resides in Microsoft Scripting Engine (Chakra); patch reference is ChakraCore v1.10.1 — systems running older ChakraCore versions are at risk
  • ·Exploit status at time of advisory was 'Publicly Disclosed: No; Exploited: No' but rated 'Exploitation More Likely' for the latest software release — no in-the-wild exploitation confirmed
  • ·CVE-2018-8279 is one of several Edge memory corruption CVEs patched together; do not conflate with CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, or CVE-2018-8301

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.