Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7942
HistoryDec 04, 2018 - 1:59 p.m.

Remote Code Execution (RCE)

2018-12-0413:59:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.203 Low

EPSS

Percentile

96.4%

Microsoft ChakraCore is vulnerable to remote code execution. This is due to a lack of checks before invocation of JavascriptPromise::AsyncSpawnStep which could allow a remote attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.