[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Scripting Engine Security Feature Bypass Vulnerability - CVE-2018-8276

ID: oval:org.secpod.oval:def:46338Date: (C)2018-07-11   (M)2024-01-19
Class: VULNERABILITYFamily: windows




A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed. By itself, the CFG bypass vulnerability does not allow arbitrary code execution. However, an attacker could use the CFG bypass vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code on a target system. To exploit the CFG bypass vulnerability, a user must be logged on to the Microsoft Chakra scripting engine and running it. The user would then need to browse to a malicious website. The security update addresses the CFG bypass vulnerability by helping to ensure that the Microsoft Chakra scripting engine properly handles accessing memory.

Platform:
Microsoft Windows 10
Product:
Microsoft Edge
Microsoft ChakraCore
Reference:
CVE-2018-8276
CVE    1
CVE-2018-8276
CPE    11
cpe:/a:microsoft:edge:-
cpe:/o:microsoft:windows_10:1703:::x64
cpe:/o:microsoft:windows_10:1703:::x86
cpe:/o:microsoft:windows_10:1709
...

© SecPod Technologies