Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7802
HistoryNov 15, 2018 - 7:27 a.m.

Remote Code Execution (RCE)

2018-11-1507:27:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.09

Percentile

94.7%

Microsoft.Chakracore is vulnerable to a remote code execution (RCE) attack. The library does not properly handle objects in memory in the GlobOpt::CheckJsArrayKills function in lib/Backend/GlobOpt.cpp, allowing a malicious user to inject and execute arbitrary code.