CVE-2017-0234
ChakraCore RCE Vulnerability
7.5
HIGH
CVSS 3.1
EPSS 55.6%
Description
A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.
How to fix CVE-2017-0234
To remediate CVE-2017-0234, upgrade the affected package to a fixed version below.
- —upgrade to 1.4.4 or later
Is CVE-2017-0234 being exploited?
Likely — EPSS is 55.6%, placing CVE-2017-0234 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.4.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |