High severityNVD Advisory· Published Nov 10, 2021· Updated Aug 4, 2024
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-42279
Description
Chakra Scripting Engine Memory Corruption Vulnerability
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.ChakraCoreNuGet | <= 1.11.24 | — |
Affected products
11- cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.19119:*:*:*:*:*:x86:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.4770:*:*:*:*:*:x86:*Range: 10.0.0
cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.2300:*:*:*:*:*:arm64:*+ 2 more
- cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.2300:*:*:*:*:*:arm64:*range: 10.0.0
- cpe:2.3:o:microsoft:windows_10_1809:10.0.18363.1916:*:*:*:*:*:x64:*range: 10.0.0
- cpe:2.3:o:microsoft:windows_10_1809:10.0.19041.1348:*:*:*:*:*:x64:*range: 10.0.0
- cpe:2.3:o:microsoft:windows_10_20H2:10.0.19042.1348:*:*:*:*:*:arm64:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_10_21H1:10.0.19043.1348:*:*:*:*:*:x64:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_11_21H2:10.0.22000.318:*:*:*:*:*:arm64:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.4770:*:*:*:*:*:*:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2300:*:*:*:*:*:*:*Range: 10.0.0
- cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.350:*:*:*:*:*:*:*Range: 10.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-jgrp-6qqq-3284ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-42279ghsaADVISORY
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42279ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.