Critical severity9.8NVD Advisory· Published Oct 10, 2018· Updated Jun 17, 2026
CVE-2018-8500
CVE-2018-8500
Description
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.ChakraCoreNuGet | < 1.11.2 | 1.11.2 |
Affected products
3cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:chakracore:-:*:*:*:*:*:*:*
- (no CPE)range: ChakraCore
Patches
Vulnerability mechanics
References
7- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8500nvdPatchVendor AdvisoryWEB
- www.securityfocus.com/bid/105463nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-fw42-4mq4-4qpqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-8500ghsaADVISORY
- github.com/chakra-core/ChakraCore/commit/cd84a0b85b4b2bcf1653c7bfd5426bbc72b2b216ghsaWEB
- github.com/chakra-core/ChakraCore/pull/5764ghsaWEB
- web.archive.org/web/20210124210846/http://www.securityfocus.com/bid/105463ghsaWEB
News mentions
0No linked articles in our index yet.