CVE-2021-42279

Severity
7.5HIGH
EPSS
3.0%
top 13.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

Chakra Scripting Engine Memory Corruption Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages17 packages

NuGetMicrosoft.ChakraCore1.11.24
CVEListV5microsoft/chakracoreN/A
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4770
CVEListV5microsoft/windows_server_201910.0.010.0.17763.2300
CVEListV5microsoft/windows_server_202210.0.010.0.20348.350

Patches

🔴Vulnerability Details

3
OSV
Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption2022-05-24
GHSA
Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption2022-05-24
CVEList
Chakra Scripting Engine Memory Corruption Vulnerability2021-11-10

📋Vendor Advisories

1
Microsoft
Chakra Scripting Engine Memory Corruption Vulnerability2021-11-09
CVE-2021-42279 (HIGH CVSS 7.5) | Chakra Scripting Engine Memory Corr | cvebase.io