CVE-2018-0925
Description
ChakraCore scripting engine contains a memory corruption vulnerability that can lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ChakraCore scripting engine contains a memory corruption vulnerability that can lead to remote code execution.
Vulnerability
The vulnerability is a memory corruption issue in the ChakraCore scripting engine [1]. It occurs due to how the engine handles objects in memory [1]. This CVE ID is unique from CVE-2018-0876, CVE-2018-0889, CVE-2018-0893, and CVE-2018-0935 [1]. References indicate the affected version is Microsoft ChakraCore 0 [3]. The flaw is classified as a failure to handle exceptional conditions [3].
Exploitation
An attacker can exploit this vulnerability remotely without local access [3]. To trigger the vulnerability, the attacker needs to craft a malicious web page that leverages the memory corruption in ChakraCore [1][3]. If a user visits this page with a browser or application that uses the vulnerable ChakraCore engine, the attacker's code can execute in the context of the current user [1]. The exploitation sequence is not detailed in the available references, but it involves the scripting engine incorrectly handling objects in memory [1].
Impact
Successful exploitation allows an attacker to achieve remote code execution [1]. The attacker gains the ability to run arbitrary code in the context of the user who is running the vulnerable application [1]. This can lead to full compromise of the affected system, including data disclosure, modification, or denial of service [1].
Mitigation
Microsoft released security updates for ChakraCore to address this vulnerability [1]. The fix was included in updates released on March 13, 2018 [3]. ChakraCore is an open-source project; Microsoft provided security updates for ChakraCore 1.11 until March 9, 2021 [2]. Users should apply the latest security patches from their software vendor. No workaround is disclosed if patching is not possible [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.ChakraCoreNuGet | < 1.8.2 | 1.8.2 |
Affected products
2- Microsoft Corporation/ChakraCorev5Range: ChakraCore
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-5q2v-52gc-4w7pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-0925ghsaADVISORY
- www.securityfocus.com/bid/103287mitrevdb-entryx_refsource_BID
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0925ghsax_refsource_CONFIRMWEB
- web.archive.org/web/20210124144841/http://www.securityfocus.com/bid/103287ghsaWEB
News mentions
0No linked articles in our index yet.