ZeroHour

CVE-2017-11767

CVSS 3.0
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".

Vendors
microsoft
Products
chakracore
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news