CVE-2017-0208
MEDIUM4.3EPSS 14.9%ChakraCore information disclosure vulnerability
Published: 5/17/2022Modified: 2/16/2024
Description
An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."
Affected packages (1)
- NuGet/Microsoft.ChakraCorefrom 0, < 1.4.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
References (7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-0208
- PATCHhttps://github.com/chakra-core/ChakraCore
- WEBhttps://github.com/chakra-core/ChakraCore/commit/54d6d085987e2c399863940179db67b594d7f0a3
- WEBhttps://github.com/chakra-core/ChakraCore/pull/2834
- WEBhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208
- WEBhttps://web.archive.org/web/20210124023848/http://www.securityfocus.com/bid/97460
- WEBhttps://web.archive.org/web/20211201121401/http://www.securitytracker.com/id/1038234