First published: Tue Apr 09 2019(Updated: )
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0861.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.11.8 | 1.11.8 |
Microsoft Edge Beta | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 | |
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2019 | ||
Microsoft Chakra | <1.11.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0860 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2019-0860, update Microsoft Edge or Microsoft ChakraCore to version 1.11.8 or later.
CVE-2019-0860 affects Microsoft Edge and Microsoft ChakraCore versions prior to 1.11.8.
Yes, CVE-2019-0860 can be exploited remotely, allowing attackers to execute arbitrary code.
If exploited, CVE-2019-0860 may allow attackers to gain control of affected systems and access sensitive user data.