vendor:
ChakraCore
by:
Microsoft
9.8
CVSS
CRITICAL
Out-of-Bounds Read
125
CWE
Product Name: ChakraCore
Affected Version From: ChakraCore v1.11.10
Affected Version To: ChakraCore v1.11.13
Patch Exists: YES
Related CWE: CVE-2018-8500
CPE: a:microsoft:chakracore:1.11.10
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Chakra InvariantBlockBackwardIterator Class Vulnerability
Chakra uses the InvariantBlockBackwardIterator class to backpropagate the information about the hoisted bound checks. But the class follows the linked list instead of the control flow. This may lead to incorrectly remove the bound checks, resulting in an Out-of-Bounds Read vulnerability.
Mitigation:
Microsoft has released a patch to address this vulnerability.