Skip to content
COOEY

EXPOSURES › CVE-2018-8298

CVE-2018-8298

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-8298 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

ChakraCore scripting engine type confusion vulnerability allows remote code execution and is actively exploited in the wild.

A type confusion flaw in the ChakraCore scripting engine enables remote code execution, posing a severe risk to systems relying on this engine. DIB organizations must ensure their software stacks are patched against this actively exploited vulnerability to prevent compromise. This failure highlights the danger of unpatched, high-severity CVEs that are already being weaponized in the wild.

Shame score — The vulnerability is actively exploited in the wild and allows remote code execution, representing a severe, avoidable risk that has been weaponized against systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.