Vulnerability record · CVE-2018-0837 · published 15 February 2018
CVE-2018-0837: Microsoft Edge and ChakraCore scripting engine memory corruption RCE
Microsoft · Chakracore
CVE-2018-0837 is a memory corruption flaw (out-of-bounds write, CWE-787) in how the Microsoft Edge and ChakraCore scripting engines handle objects in memory. Successful exploitation allows remote code execution in the context of the affected browser or script host. It affects Windows 10 (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016.
Description
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0858, CVE-2018-0859, CVE-2018-0860, CVE-2018-0861, and CVE-2018-0866.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.5 with a public exploit and very high EPSS (99.2nd percentile) make this a serious remote code execution risk despite the High attack complexity and required user interaction.
What it is
CVE-2018-0837 is a memory corruption flaw (out-of-bounds write, CWE-787) in how the Microsoft Edge and ChakraCore scripting engines handle objects in memory. Successful exploitation allows remote code execution in the context of the affected browser or script host. It affects Windows 10 (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016.
Impact
An attacker who exploits the flaw can execute arbitrary code in the context of the current user, potentially taking full control of the affected system. Because the flaw is in the scripting engine, code execution occurs within the browser or ChakraCore host process.
Attack surface
Reached remotely over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically a victim visiting a crafted web page or opening malicious content that triggers the scripting engine. Attack complexity is rated High (AC:H).
Exploitation
A public exploit exists (Exploit-DB 44081), and EPSS is high at 0.653 (99.2nd percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-0837 as the primary fix.
- Upgrade or remove unsupported Windows 10 builds (Gold, 1511, 1607, 1703, 1709) that no longer receive security updates.
- Ensure ChakraCore-based applications are updated to a patched version or migrated off the vulnerable engine.
- Enforce browser hardening such as Enhanced Mitigation Experience Toolkit/Exploit Protection and disable unnecessary scripting where feasible.
- Restrict user browsing to trusted sites and block known exploit-hosting domains at the network layer.
Detection
- Monitor for crashes or abnormal termination of Microsoft Edge (MicrosoftEdge.exe) and ChakraCore host processes, which can indicate memory corruption attempts.
- Hunt for exploit-related network traffic or downloads matching known PoC patterns associated with Exploit-DB 44081.
- Review endpoint telemetry for suspicious child processes spawned by Edge or ChakraCore hosts, a common post-exploitation indicator.
- Track patch status of Windows 10 and Windows Server 2016 systems against the MSRC advisory to find unpatched assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102876 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040372 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0837 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44081/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102876 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040372 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0837 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44081/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-0837 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0837), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.