Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8011
HistoryDec 11, 2018 - 5:01 a.m.

Remote Code Execution (RCE)

2018-12-1105:01:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.94 High

EPSS

Percentile

99.2%

microsoft.chakracore is vulnerable to remote code execution. This is due to a use-after-free bug where ServerScriptContext is freed before being unregistered, which would allow an attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2017-8499, CVE-2017-8521, CVE-2017-8548, and CVE-2017-8549.