RULE(RULE ID:320492)

Rule General Information
Release Date: 2017-09-14
Rule Name: Microsoft Edge Chakra Eval Integer Overflow Vulnerability -1 (CVE-2017-8636)
Severity:
CVE ID:
Rule Protection Details
Description: An integer overflow vulnerability exists in Microsoft Edge Chakra JavaScript Engine. The vulnerability is due to an overly large size of the eval() function argument with new() operator.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: SecurityFocusBID:100056
SecurityTrackerID:1039095
ExploitDB:42466
ExploitDB:42468
Solutions
Update vendor's patch.