Vulnerability CVE-2017-0223


Published: 2017-05-15

Description:
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Microsoft -> EDGE 

 References:
http://www.securitytracker.com/id/1038425
https://github.com/Microsoft/ChakraCore/pull/2959

Copyright 2024, cxsecurity.com

 

Back to Top