Vulnerability record · CVE-2018-8139 · published 9 May 2018
CVE-2018-8139: Microsoft Edge and ChakraCore scripting engine memory corruption RCE
Microsoft · Edge
Microsoft Edge and ChakraCore contain a memory corruption flaw in the scripting engine's handling of objects in memory, classified as an out-of-bounds read (CWE-125). Successful exploitation allows remote code execution in the context of the affected browser or script host. The record does not specify affected versions beyond the product names Edge and ChakraCore.
Description
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 3.0 base score is 7.5 (HIGH) with network reachability and high confidentiality, integrity, and availability impact, and a public exploit plus very high EPSS percentile raise real-world risk.
What it is
Microsoft Edge and ChakraCore contain a memory corruption flaw in the scripting engine's handling of objects in memory, classified as an out-of-bounds read (CWE-125). Successful exploitation allows remote code execution in the context of the affected browser or script host. The record does not specify affected versions beyond the product names Edge and ChakraCore.
Impact
An attacker who convinces a user to load crafted content can corrupt memory and execute arbitrary code in the scripting engine's context, potentially leading to full compromise of the browsing session or host.
Attack surface
Reached over the network via crafted web content or script processed by the Edge scripting engine or ChakraCore; no privileges are required, but user interaction (UI:R) is needed to trigger rendering or execution of the malicious content.
Exploitation
Not listed in CISA KEV, but an Exploit-DB entry (45012) tagged as an exploit exists, and EPSS shows a 30-day probability of 0.66845 (99.2nd percentile), indicating high predicted exploitation activity.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8139.
- Upgrade or retire ChakraCore-based components and ensure Edge is on a supported, patched build.
- Enforce browser isolation or sandboxing and block untrusted script execution where feasible.
- Restrict or monitor user browsing to reduce exposure to malicious pages that trigger the scripting engine flaw.
Detection
- Monitor for crashes or abnormal terminations of Edge or ChakraCore processes that may indicate memory corruption attempts.
- Hunt for exploit artifacts matching Exploit-DB 45012 in proxy, email, or web gateway logs.
- Correlate endpoint telemetry for suspicious child processes spawned by browser processes.
- Track EPSS and vendor advisories for renewed exploitation activity against unpatched Edge or ChakraCore installs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103977 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040844 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8139 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45012/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/103977 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040844 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8139 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45012/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8139 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.