Vulnerability record · CVE-2018-8279 · published 11 July 2018
CVE-2018-8279: Microsoft Edge and ChakraCore type confusion remote code execution
Microsoft · Edge
Microsoft Edge and ChakraCore improperly access objects in memory, resulting in a type confusion (CWE-843) that can be triggered remotely. A crafted page can corrupt memory and execute code in the browser's context, which matters because the browser is a common entry point for drive-by attacks.
Description
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a widely deployed browser with public exploit code and very high EPSS, though it requires user interaction and is not in KEV.
What it is
Microsoft Edge and ChakraCore improperly access objects in memory, resulting in a type confusion (CWE-843) that can be triggered remotely. A crafted page can corrupt memory and execute code in the browser's context, which matters because the browser is a common entry point for drive-by attacks.
Impact
An attacker who successfully triggers the flaw can execute arbitrary code with the privileges of the affected browser or script engine process.
Attack surface
Reached over the network via a crafted web page or content rendered by Edge or ChakraCore; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must open or view the malicious content.
Exploitation
Not listed in CISA KEV, but EPSS is 0.70729 (99.36th percentile) and a public Exploit-DB entry (45214) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8279.
- Keep Edge, Windows, and any ChakraCore-based applications fully patched.
- Restrict or block untrusted web content and script execution where feasible.
- Reduce reliance on legacy Edge/ChakraCore by migrating to a currently supported browser.
- Monitor vendor advisories for related Edge memory corruption fixes.
Detection
- Hunt for Edge or ChakraCore process crashes consistent with memory corruption.
- Monitor for suspicious child processes spawned by browser processes.
- Review proxy and DNS logs for known exploit-hosting or malicious domains.
- Alert on unusual script or shellcode-like activity originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104641 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041256 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8279 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45214/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/104641 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041256 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8279 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45214/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8279 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8279), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.