RULE(RULE ID:338319)

Rule General Information
Release Date: 2024-08-20
Rule Name: Microsoft Scripting Engine Memory Corruption Vulnerability (CVE-2024-38178)
Severity:
CVE ID:
Rule Protection Details
Description: The vulnerability in question is a Windows Scripting Languages Remote Code Execution Vulnerability that occurs in jscript9.dll. The vulnerability that occurs is Type Confusion, which occurs during the optimization process.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows, Linux, Others
Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178
Solutions
Refer to the announcement or patch by the vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178