Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7949
HistoryDec 04, 2018 - 2:28 p.m.

Remote Code Execution (RCE)

2018-12-0414:28:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.203 Low

EPSS

Percentile

96.4%

Microsoft ChakraCore is vulnerable to remote code execution. This is due to buffer overflow bug in GlobOpt.cpp which would allow a remote attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.