Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8128
HistoryJan 09, 2019 - 3:01 a.m.

Remote Code Execution (RCE)

2019-01-0903:01:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.966 High

EPSS

Percentile

99.6%

Microsoft.ChakraCore is vulnerable to remote code execution. This is due to a type confusion via NewScObjectNoCtor or InitProto which would allow an attacker to execute arbitrary code in the context of the authenticated user. This CVE ID is different from CVE-2019-0539, CVE-2019-0568.