HIGH

CVE-2018-8145

CVSS v3

7.5

HIGH

EPSS Score

72.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.

Technical details

Published
5/9/2018
Exploit-DB
EDB-45011

Frequently asked questions

What is CVE-2018-8145?

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.

Is CVE-2018-8145 actively exploited?

Active exploitation of CVE-2018-8145 has not been confirmed. The EPSS score is 72.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-8145?

CVE-2018-8145 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2018-8145 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.