CVE-2019-0938: Critical severity microsoft edge beta vulnerability
Published May 16, 2019
·Updated
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Affected Software
10 affected components
Microsoft Edge
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Remediation
Event History
May 16, 2019
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0938?
CVE-2019-0938 is considered to be of medium severity.
2
How do I fix CVE-2019-0938?
To mitigate CVE-2019-0938, ensure that Microsoft Edge is updated to the latest version.
3
Which versions of Microsoft Edge are affected by CVE-2019-0938?
CVE-2019-0938 affects Microsoft Edge running on various versions of Windows 10 prior to the update.
4
Can CVE-2019-0938 lead to remote code execution?
CVE-2019-0938 does not directly lead to remote code execution but allows elevation of privilege within the system.
5
Is Microsoft Windows Server affected by CVE-2019-0938?
CVE-2019-0938 does not affect Microsoft Windows Server 2016 or 2019, as those versions are not vulnerable.