Files
CVEs-PoC/2018/CVE-2018-8288.md
T
2025-09-29 21:09:30 +02:00

40 lines
3.4 KiB
Markdown

### [CVE-2018-8288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8288)
![](https://img.shields.io/static/v1?label=Product&message=ChakraCore&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Internet%20Explorer%2011&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Edge&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=ChakraCore%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201607%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201607%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201703%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201703%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201709%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201709%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201803%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201803%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%207%20for%2032-bit%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%207%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%208.1%20for%2032-bit%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%208.1%20for%20x64-based%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20RT%208.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202012%20R2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202016%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Remote%20Code%20Execution&color=brightgreen)
### Description
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298.
### POC
#### Reference
- https://www.exploit-db.com/exploits/45213/
#### Github
- https://github.com/addicjanov/js-vuln-db
- https://github.com/otravidaahora2t/js-vuln-db
- https://github.com/tunz/js-vuln-db