CVE-2017-0223
CRITICAL9.8EPSS 36.0%ChakraCore RCE Vulnerability
Published: 5/17/2022Modified: 2/16/2024
Description
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.
Affected packages (1)
- NuGet/Microsoft.ChakraCorefrom 0, < 1.4.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-0223
- PATCHhttps://github.com/chakra-core/ChakraCore
- WEBhttps://github.com/chakra-core/ChakraCore/commit/f74773f4520adff6b70a7d445417aa9769f61fa6
- WEBhttps://github.com/chakra-core/ChakraCore/pull/2959
- WEBhttps://github.com/Microsoft/ChakraCore/pull/2959
- WEBhttps://web.archive.org/web/20210124184849/http://www.securitytracker.com/id/1038425