CVE-2018-8354

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8391, CVE-2018-8456, CVE-2018-8457, CVE-2018-8459.

References

http://www.securityfocus.com/bid/105232

http://www.securitytracker.com/id/1041623

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8354

Details

Source: MITRE

Published: 2018-09-13

Updated: 2020-08-24

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 4.9

Severity: HIGH

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.6

Severity: HIGH

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
117417KB4457142: Windows 10 Version 1709 and Windows Server Version 1709 September 2018 Security UpdateNessusWindows : Microsoft Bulletins
critical
117416KB4457138: Windows 10 Version 1703 September 2018 Security UpdateNessusWindows : Microsoft Bulletins
critical
117414KB4457132: Windows 10 September 2018 Security UpdateNessusWindows : Microsoft Bulletins
critical
117413KB4457131: Windows 10 Version 1607 and Windows Server 2016 September 2018 Security UpdateNessusWindows : Microsoft Bulletins
critical
117411KB4457128: Windows 10 Version 1803 and Windows Server Version 1803 September 2018 Security UpdateNessusWindows : Microsoft Bulletins
critical