CVE-2020-17131

Severity
7.5HIGH
EPSS
1.2%
top 21.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateApr 13

Description

Chakra Scripting Engine Memory Corruption Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages4 packages

CVEListV5microsoft/chakracore< publication
NVDmicrosoft/chakracore< 1.11.0
NuGetMicrosoft.ChakraCore< 1.11.24
CVEListV5microsoft/microsoft_edge_(edgehtml-based)1.0..0publication

Patches

🔴Vulnerability Details

3
GHSA
Out-of-bounds Write in Chakra2021-04-13
OSV
Out-of-bounds Write in Chakra2021-04-13
CVEList
Chakra Scripting Engine Memory Corruption Vulnerability2020-12-09

📋Vendor Advisories

1
Microsoft
Chakra Scripting Engine Memory Corruption Vulnerability2020-12-08
CVE-2020-17131 (HIGH CVSS 7.5) | Chakra Scripting Engine Memory Corr | cvebase.io