CVE-2018-8145
CVE-2018-8145
Vexday Risk Score
35Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 67.2%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
09 May 2018Published on NVD
12 Jul 2018Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.
Affected products
Microsoft · ChakraCoreMicrosoft · Internet Explorer 10Microsoft · Internet Explorer 11Microsoft · Microsoft Edgepublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/45011/unverifiedexploitdbwww.exploit-db.com/exploits/45011unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →