Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6920
HistoryJul 04, 2018 - 8:12 a.m.

Remote Code Execution (RCE)

2018-07-0408:12:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
31

EPSS

0.947

Percentile

99.3%

microsoft.chakracore is vulnerable to remote code execution. It exists because the CreateLabel function in IRBuilderAsmJs.cpp, does not properly check instrPrevparameter, causing memory corruption which allows attacker to trigger RCE. This CVE ID is different from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930. This vulnerability also affects Microsoft Edge in Windows and Windows Server 2016.