Skip to content
COOEY

EXPOSURES › CVE-2018-17480

CVE-2018-17480

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-17480 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.

This vulnerability in the Chromium V8 engine enables remote code execution within a sandbox, affecting numerous browsers and posing a significant risk to DIB organizations reliant on these platforms. Failure to promptly patch exposes systems to potential compromise and impacts NIST 800-171 compliance requirements related to vulnerability management. Immediate patching and browser updates are critical.

Shame score — The vulnerability's active exploitation and potential for widespread impact, despite being a known issue, demonstrates a concerning lack of proactive security measures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized