CISA Known Exploited Vulnerability

CVE-2018-8298

ChakraCore · ChakraCore scripting engine

ChakraCore Scripting Engine Type Confusion Vulnerability

Date added
BOD 22-01 due date
CWE CWE-843
Ransomware Unknown

CISA description

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

Required action

Apply updates per vendor instructions.