Vulnerability record · CVE-2018-8291 · published 11 July 2018
CVE-2018-8291: Microsoft browser scripting engine type confusion allows remote code execution
Microsoft · Internet Explorer
A type confusion flaw in the scripting engine (ChakraCore) used by Internet Explorer 11, Microsoft Edge and ChakraCore causes memory corruption when objects are handled in memory. Because the corruption occurs in the JavaScript engine, it can be turned into remote code execution in the browser process. The record does not list specific affected versions beyond the three named products.
Description
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in widely deployed browsers with public exploit code and very high EPSS, though exploitation requires user interaction and no KEV listing.
What it is
A type confusion flaw in the scripting engine (ChakraCore) used by Internet Explorer 11, Microsoft Edge and ChakraCore causes memory corruption when objects are handled in memory. Because the corruption occurs in the JavaScript engine, it can be turned into remote code execution in the browser process. The record does not list specific affected versions beyond the three named products.
Impact
An attacker who gets a victim to load crafted content can corrupt memory and execute arbitrary code in the context of the browser, typically leading to full compromise of the user's session and machine.
Attack surface
Reached over the network through a web page or other content rendered by the affected browser; the CVSS vector shows no privileges required but user interaction required, so the victim must open or view the malicious content.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.69009, 99.3rd percentile) and a public Exploit-DB entry (45215) exists, indicating working exploit code is available.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8291 as the first action.
- Retire or disable Internet Explorer 11 and legacy ChakraCore-based rendering where business use allows.
- Keep Edge and all browser components on current supported builds.
- Enforce script and content restrictions (blocking untrusted sites, disabling unnecessary scripting) to reduce exposure until patching completes.
Detection
- Monitor browser processes (iexplore.exe, MicrosoftEdge.exe) for unexpected child processes or script interpreters.
- Hunt for crashes in the scripting engine (chakra.dll) correlated with browsing of untrusted sites.
- Review proxy and DNS logs for known exploit-hosting domains and drive-by pages delivering browser exploits.
- Use EDR to flag memory-protection events or anomalous code execution originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104637 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041256 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041258 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8291 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45215/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/104637 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041256 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041258 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8291 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45215/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8291 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8291), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.