vendor:
ChakraCore
by:
Project Zero Team
4
CVSS
MEDIUM
Bailout vulnerability
749
CWE
Product Name: ChakraCore
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: a:microsoft:chakracore
Platforms Tested: Windows
2018
Bailout vulnerability in ChakraCore
The Bailout vulnerability in ChakraCore allows an attacker to directly change the opcode of an instruction that cannot be JITed, leading to the generation of bailouts. This can be done by modifying the method 'Lowerer::GenerateBailOut'. The vulnerability occurs when a Call instruction has 'Src2'.
Mitigation:
Apply the patch provided by the vendor.