Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8124
HistoryJan 09, 2019 - 2:32 a.m.

Remote Code Execution (RCE)

2019-01-0902:32:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.966 High

EPSS

Percentile

99.6%

Microsoft.ChakraCore is vulnerable to remote code execution. This is due to a type confusion via NewScObjectNoCtor or InitProto which would allow an attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2019-0567, CVE-2019-0568.