
C'è un heap overflow classico quando si valuta (eval) una stringa abbastanza grande in Chakra! Questo problema può essere riprodotto costantemente nell'Edge aggiornato in Win10 WIP. Verrà generata un'eccezione immediatamente all'apertura di POC.html in Edge.
I browser Microsoft in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 e Windows RT 8.1, Windows Server 2012 e R2, Windows 10 Gold, 1511, 1607, 1703 e Windows Server 2016 consentono a un utente malintenzionato di eseguire codice arbitrario nel contesto dell'utente corrente a causa del modo in cui i motori JavaScript dei browser Microsoft eseguono il rendering durante la gestione di oggetti in memoria, nota come "Scripting Engine Memory Corruption Vulnerability". Questo ID CVE è diverso da CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672 e CVE-2017-8674.
====================================================================||> ====================================================================||>

====================================================================||> ====================================================================||>