PT-2020-4692 · Microsoft · Chakra Scripting Engine+1

Published

2020-11-10

·

Updated

2023-12-31

·

CVE-2020-17048

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chakra Scripting Engine (affected versions not specified)
Description The issue is related to a memory corruption vulnerability in the Chakra scripting engine, which can be caused by a buffer overflow. This can allow a remote attacker to disclose protected information. The vulnerability may also lead to remote code execution due to type confusion in the Chakra array iterator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2020-05244
CVE-2020-17048
GHSA-VPC2-7XMF-PPMF
ZDI-20-1370

Affected Products

Chakra Scripting Engine
Edge