Remote Code Execution Vulnerability in Microsoft Edge's Chakra Scripting Engine
CVE-2019-1307

7.5HIGH

Summary

A remote code execution vulnerability exists in Microsoft Edge due to improper handling of objects in memory by the Chakra scripting engine. An attacker who successfully exploits this vulnerability could run arbitrary code in the context of the current user. To exploit this vulnerability, an attacker could host a malicious web site that is designed to exploit the vulnerability through a web browser and then convince a user to visit that website. Successful exploitation could allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability highlights the importance of keeping web browsers updated and practicing safe browsing habits.

Affected Version(s)

ChakraCore = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems = unspecified

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.