Vulnerability record · CVE-2018-8133 · published 9 May 2018
CVE-2018-8133: Microsoft Edge Chakra scripting engine type confusion allows remote code execution
Microsoft · Edge
CVE-2018-8133 is a type confusion (CWE-843) in the Chakra scripting engine used by Microsoft Edge and ChakraCore, caused by improper handling of objects in memory. A remote attacker who convinces a user to open a crafted page can corrupt memory and execute code in the context of the browser. It matters because the affected engine is the default script engine in Edge, and the flaw is remotely reachable with only user interaction.
Description
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8145, CVE-2018-8177.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser engine with a public exploit and very high EPSS, though exploitation requires user interaction and no KEV listing confirms active attacks.
What it is
CVE-2018-8133 is a type confusion (CWE-843) in the Chakra scripting engine used by Microsoft Edge and ChakraCore, caused by improper handling of objects in memory. A remote attacker who convinces a user to open a crafted page can corrupt memory and execute code in the context of the browser. It matters because the affected engine is the default script engine in Edge, and the flaw is remotely reachable with only user interaction.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the Edge or ChakraCore process, which can lead to full compromise of the user's session and data. The CVSS 3.0 vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network (AV:N) by a crafted web page or script processed by the Chakra engine; no authentication is required (PR:N) but a user must interact, typically by visiting or opening the malicious content (UI:R).
Exploitation
A public exploit exists per the Exploit-DB reference, and EPSS is high (0.50858, 98.9th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this data.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8133 as the first action.
- Update or retire ChakraCore-based components that embed the vulnerable engine.
- Where Edge cannot be patched immediately, restrict browsing to trusted sites and block untrusted script content via policy.
- Consider disabling or removing legacy Edge/ChakraCore components that are no longer required.
Detection
- Monitor for Edge or ChakraCore process crashes and abnormal memory corruption events on endpoints.
- Hunt for exploit artifacts matching the public Exploit-DB PoC (44817) in proxy, email or web gateway logs.
- Alert on suspicious child processes spawned by Edge or ChakraCore, which can indicate successful code execution.
- Track unpatched Edge/ChakraCore versions in asset inventory against the MSRC advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103982 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040844 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8133 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44817/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/103982 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040844 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8133 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44817/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.