Segmentation Violation in ChakraCore Master Branch Affecting Microsoft
CVE-2023-37142

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
18 July 2023

Summary

A segmentation violation has been identified in the ChakraCore master branch, specifically within the Js::EntryPointInfo::HasInlinees() function. This vulnerability may allow an attacker to exploit the JavaScript engine, potentially leading to unexpected behavior or crashes in applications utilizing ChakraCore. It is crucial for developers and system administrators using this engine to review the impact and apply necessary updates to mitigate potential risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.