RULE(RULE ID:320513)

Rule General Information
Release Date: 2017-09-21
Rule Name: Microsoft Edge Chakra Eval Integer Overflow Vulnerability -2 (CVE-2017-8641)
Severity:
CVE ID:
Rule Protection Details
Description: An integer overflow vulnerability exists in Microsoft Edge Chakra JavaScript Engine. The vulnerability is due to an overly large size of the eval() function argument.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: SecurityFocusBID:100057
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8641
SecurityTrackerID:1039095
ExploitDB:42465
Solutions
Applying the patch KB4034668 is able to eliminate this problem. The bugfix is ready for download at https://www.catalog.update.microsoft.com/Search.aspx?q=KB4034668