CVE-2018-0859

high

Description

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0858, CVE-2018-0860, CVE-2018-0861, and CVE-2018-0866.

References

https://github.com/advisories/GHSA-7gjv-9m33-chg8

https://github.com/advisories/GHSA-399v-jg88-3gx6

https://github.com/advisories/GHSA-v3xp-3wpq-rvhp

https://github.com/advisories/GHSA-q9x6-7hjh-q9fc

https://github.com/advisories/GHSA-j762-mr2c-fmp9

https://github.com/advisories/GHSA-9pvj-pgg9-pvqq

https://github.com/advisories/GHSA-m8x8-5ch7-c5w9

https://github.com/advisories/GHSA-h9wf-mpvf-9jqg

https://github.com/advisories/GHSA-5j48-826p-2w9r

https://github.com/advisories/GHSA-3cwf-pwcg-57xr

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0859

http://www.securitytracker.com/id/1040372

http://www.securityfocus.com/bid/102882

Details

Source: Mitre, NVD

Published: 2018-02-15

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.17872