Lucene search

K
zdiBruno Keith (@bkth_)ZDI-19-179
HistoryFeb 12, 2019 - 12:00 a.m.

Microsoft Chakra JavaScript Loop Type Confusion Vulnerability

2019-02-1200:00:00
Bruno Keith (@bkth_)
www.zerodayinitiative.com
7

0.082 Low

EPSS

Percentile

94.4%

This vulnerability allows remote attackers to produce abnormal program execution on vulnerable installations of Microsoft Chakra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the JIT compilation of loops. By performing actions in JavaScript, an attacker can trigger a type confusion condition. It may be possible for an attacker to leverage this vulnerability to execute arbitrary code in the context of the current process.