CVE-2020-17054

Severity
7.5HIGH
EPSS
1.7%
top 17.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateAug 2

Description

Chakra Scripting Engine Memory Corruption Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages4 packages

CVEListV5microsoft/chakracore< publication
NVDmicrosoft/chakracore1.11.01.11.23
NuGetMicrosoft.ChakraCore< 1.11.23
CVEListV5microsoft/microsoft_edge_(edgehtml-based)1.0..0publication

Patches

🔴Vulnerability Details

4
OSV
Out-of-bounds Write in ChakraCore2021-08-02
GHSA
Out-of-bounds Write in ChakraCore2021-08-02
GHSA
Out-of-bounds Write in ChakraCore2021-08-02
CVEList
Chakra Scripting Engine Memory Corruption Vulnerability2020-11-11

📋Vendor Advisories

1
Microsoft
Chakra Scripting Engine Memory Corruption Vulnerability2020-11-10
CVE-2020-17054 (HIGH CVSS 7.5) | Chakra Scripting Engine Memory Corr | cvebase.io