SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-17480

Google Chromium V8 Out-of-Bounds Write Vulnerability

KEVHIGH 8.8EPSS 35.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
35.64% probability · 98th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-787
Affected
google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux
Source
chrome-cve-admin@google.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-17480

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.