Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8012
HistoryDec 11, 2018 - 5:07 a.m.

Remote Code Execution (RCE)

2018-12-1105:07:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
26

EPSS

0.104

Percentile

95.1%

microsoft.chakracore is vulnerable to remote code execution. This is due to a buffer overflow in TypeHandler caused by an invalid index reuse, which would allow an attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2017-8517 and CVE-2017-8524.