#VU14770 Buffer over-read in Microsoft products - CVE-2018-8315
Published: September 13, 2018
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary error while handling object types when parsing HTML content. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds read and gain access to contents of memory.