PT-2021-4876 · Microsoft · Chakra Scripting Engine+2

Published

2021-11-09

·

Updated

2023-12-28

·

CVE-2021-42279

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chakra Scripting Engine versions (affected versions not specified) ChakraCore versions (affected versions not specified)
Description The issue is related to a memory corruption vulnerability in the Chakra Scripting Engine, caused by an out-of-bounds write operation. This can allow a remote attacker to execute arbitrary code. The vulnerability affects the Chakra Scripting Engine and ChakraCore.
Recommendations For Chakra Scripting Engine, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For ChakraCore, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2021-05606
CVE-2021-42279
GHSA-JGRP-6QQQ-3284

Affected Products

Chakra Scripting Engine
Chakracore
Windows