HTTP: Microsoft Edge Chakra ToDefiniteAnyNumber Type Confusion

A type confusion vulnerability has been reported in Microsoft Edge Chakra JavaScript Engine. A remote attacker could exploit these vulnerabilities by enticing the target user to open a specially crafted web page or document. Successful exploitation, in the worst case, could lead to arbitrary code execution in the security context of the target user.

Extended Description

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

References

BugTraq: 101734

CVE: CVE-2017-11840

Short Name
HTTP:STC:IE:EDGE-CHAKRA-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-11840 Chakra Confusion Edge Microsoft ToDefiniteAnyNumber Type bid:101734
Release Date
01/02/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3813
False Positive
Unknown
CVSS Score

7.6

Found a potential security threat?