CVE-2018-8315
published 2018-09-13CVE-2018-8315: An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information…
PriorityP418medium4.2CVSS 3.0
AVNACHPRNUIRSUCLILAN
EPSS
3.12%
86.4th percentile
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chakracore | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
CVSS provenance
nvdv3.04.2MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Internet Explorer 10/11 Scripting Engine information disclosure (EUVD-2022-3282 / Nessus ID 117415)
vuldb·2026-05-19·CVSS 4.2
CVE-2018-8315 [MEDIUM] Microsoft Internet Explorer 10/11 Scripting Engine information disclosure (EUVD-2022-3282 / Nessus ID 117415)
A vulnerability has been found in Microsoft Internet Explorer 10/11 and classified as problematic. This impacts an unknown function of the component Scripting Engine. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2018-8315. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.
VulDB
Microsoft Edge/ChakraCore Scripting Engine information disclosure (EUVD-2022-3282 / Nessus ID 117415)
vuldb·2026-05-19·CVSS 4.2
CVE-2018-8315 [MEDIUM] Microsoft Edge/ChakraCore Scripting Engine information disclosure (EUVD-2022-3282 / Nessus ID 117415)
A vulnerability, which was classified as problematic, was found in Microsoft Edge and ChakraCore. This affects an unknown function of the component Scripting Engine. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2018-8315. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
ChakraCore information disclosure vulnerability
ghsa·2022-05-14
CVE-2018-8315 [MEDIUM] CWE-200 ChakraCore information disclosure vulnerability
ChakraCore information disclosure vulnerability
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
OSV
ChakraCore information disclosure vulnerability
osv·2022-05-14
CVE-2018-8315 [MEDIUM] ChakraCore information disclosure vulnerability
ChakraCore information disclosure vulnerability
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
Microsoft
Microsoft Scripting Engine Information Disclosure Vulnerability
vendor_msrc·2018-09-11·CVSS 4.2
CVE-2018-8315 [MEDIUM] Microsoft Scripting Engine Information Disclosure Vulnerability
Microsoft Scripting Engine Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the browser scripting engine improperly handle object types.
An attacker who has successfully exploited this vulnerability might be able to read privileged data across trust boundaries. In browsing scenarios, an attacker could convince a user to visit a malicious site and leverage the vulnerability to obtain privileged information from the browser process,
such as sensitive data from other opened tabs. An attacker could also inject malicious code into advertising networks used by trusted sites or embed malicious code on a compromised, but trusted, site.
The security update addresses the vulnerability by correcting how the browser scripting engine handles object
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
http://www.securityfocus.com/bid/105251http://www.securitytracker.com/id/1041623https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8315http://www.securityfocus.com/bid/105251http://www.securitytracker.com/id/1041623https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8315
2018-09-13
Published