EXPOSURES › CVE-2018-8298
CVE-2018-8298
HIGH ⌖ ON CISA KEV · EXPLOITEDChakraCore scripting engine type confusion vulnerability allows remote code execution and is actively exploited in the wild.
A type confusion flaw in the ChakraCore scripting engine enables remote code execution, posing a severe risk to systems relying on this engine. DIB organizations must ensure their software stacks are patched against this actively exploited vulnerability to prevent compromise. This failure highlights the danger of unpatched, high-severity CVEs that are already being weaponized in the wild.
Shame score — The vulnerability is actively exploited in the wild and allows remote code execution, representing a severe, avoidable risk that has been weaponized against systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.