Security restrictions bypass in Microsoft Edge - CVE-2018-0818

 

Security restrictions bypass in Microsoft Edge - CVE-2018-0818

Published: January 3, 2018 / Updated: January 9, 2018


Vulnerability identifier: #VU9848
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0818
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to an error in Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed. A remote attacker can create a specially crafted website, trick the victim into visiting it, and bypass implemented CFG.

This vulnerability can be used along with another vulnerability to successfully compromise the affected system.

Affected software

Microsoft Edge
ChakraCore

How to mitigate CVE-2018-0818

Install updates from vendor's website.


External References

Related Security Bulletins