CVE-2020-17048

Severity
8.1HIGH
EPSS
2.2%
top 15.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateAug 2

Description

Chakra Scripting Engine Memory Corruption Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages3 packages

CVEListV5microsoft/chakracore< publication
NuGetMicrosoft.ChakraCore< 1.11.23
CVEListV5microsoft/microsoft_edge_(edgehtml-based)1.0..0publication

Patches

🔴Vulnerability Details

4
GHSA
Out-of-bounds Write in ChakraCore2021-08-02
OSV
Out-of-bounds Write in ChakraCore2021-08-02
GHSA
Out-of-bounds Write in ChakraCore2021-08-02
CVEList
Chakra Scripting Engine Memory Corruption Vulnerability2020-11-11

📋Vendor Advisories

1
Microsoft
Chakra Scripting Engine Memory Corruption Vulnerability2020-11-10
CVE-2020-17048 (HIGH CVSS 8.1) | Chakra Scripting Engine Memory Corr | cvebase.io