ChakraCore vulnerable to privilege escalation
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 10, 2023
Description
Published by the National Vulnerability Database
Nov 2, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 26, 2023
Last updated
Oct 10, 2023
ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
References