Vulnerability record · CVE-2018-0980 · published 12 April 2018
CVE-2018-0980: Microsoft Edge Chakra Engine Out-of-Bounds Write RCE
Microsoft · Edge
CVE-2018-0980 is a remote code execution flaw in the Chakra scripting engine used by Microsoft Edge and ChakraCore, caused by an out-of-bounds write (CWE-787) when handling objects in memory. An attacker who convinces a user to open a crafted page can corrupt memory and potentially execute code in the browser's context. It is one of several similar Chakra memory corruption issues patched in April 2018.
Description
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0979, CVE-2018-0990, CVE-2018-0993, CVE-2018-0994, CVE-2018-0995, CVE-2018-1019.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the requirement for user interaction and the absence of KEV listing keep it below critical.
What it is
CVE-2018-0980 is a remote code execution flaw in the Chakra scripting engine used by Microsoft Edge and ChakraCore, caused by an out-of-bounds write (CWE-787) when handling objects in memory. An attacker who convinces a user to open a crafted page can corrupt memory and potentially execute code in the browser's context. It is one of several similar Chakra memory corruption issues patched in April 2018.
Impact
Successful exploitation gives the attacker code execution with the privileges of the affected process, typically the browser or a script host, which can lead to full system compromise depending on the sandbox and user rights.
Attack surface
Reached over the network via a crafted web page or script content rendered by Edge or ChakraCore; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must be lured into viewing the malicious content.
Exploitation
A public exploit exists (Exploit-DB 44653) and EPSS is high at 0.66845 (99.257th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for Edge and ChakraCore.
- Keep Edge and any ChakraCore-based applications current with the latest cumulative updates.
- Restrict or block untrusted script content and untrusted sites through browser policy where feasible.
- Reduce user exposure by enforcing least privilege and keeping browser sandboxing enabled.
Detection
- Monitor for crashes or abnormal terminations of Microsoft Edge or ChakraCore processes.
- Hunt for exploit artifacts or known PoC signatures tied to Exploit-DB 44653 in web proxy or endpoint logs.
- Review browser and endpoint telemetry for suspicious script execution or memory corruption indicators on hosts running affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103626 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040650 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0980 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44653/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/103626 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040650 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0980 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44653/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-0980 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0980), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.