First published: Tue Mar 05 2019(Updated: )
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.11.6 | 1.11.6 |
Microsoft Edge | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2019 | ||
Microsoft ChakraCore | <1.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0649 is classified as a critical elevation of privilege vulnerability in the Microsoft Chakra JIT server.
To fix CVE-2019-0649, upgrade to a patched version of Microsoft ChakraCore, specifically version 1.11.6 or later.
CVE-2019-0649 affects Microsoft ChakraCore versions prior to 1.11.6 and is also associated with the Microsoft Edge browser.
Microsoft Windows 10 is not affected by CVE-2019-0649, but it is associated with the Microsoft ChakraCore engine used in Edge.
CVE-2019-0649 can potentially be exploited remotely if an attacker succeeds in executing malicious scripts in the context of the Microsoft Chakra JIT server.