Back

CVE-2018-8319

CRITICAL

A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library.

Published: Jul 11, 2018 Modified: Jun 17, 2026
CWE-682

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
microsoft research_javascript_cryptography_library 1.4

GitHub Security Advisory GHSA-qg3g-2mgh-33j8

Sensitive Data Exposure in msrcrypto

npm msrcrypto < 1.4.1 Fixed: 1.4.1

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 7.03%

Top 6% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub