Lucene search

K
zdiBruno Keith (@bkth_)ZDI-20-1370
HistoryNov 11, 2020 - 12:00 a.m.

Microsoft Chakra Array Iterator Type Confusion Remote Code Execution Vulnerability

2020-11-1100:00:00
Bruno Keith (@bkth_)
www.zerodayinitiative.com
31

0.003 Low

EPSS

Percentile

68.3%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Chakra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of array iterator objects. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.