Lucene search

K
osvGoogleOSV:GHSA-9F2P-WM46-6M5F
HistoryMay 17, 2022 - 12:19 a.m.

Chakra Core vulnerable to privilege escalation when writing to JavaScript null scope objects

2022-05-1700:19:55
Google
osv.dev
20
chakra core
privilege escalation
javascript
null scope objects
memory handling
windows 10
windows server
cve-2017-11836
scripting engine

EPSS

0.935

Percentile

99.2%

ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory. This could be exploited using write-AV when writing to a slot of a JavaScript null scope object.

This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11871, and CVE-2017-11873.