First published: Thu May 16 2019(Updated: )
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0938 is considered to be of medium severity.
To mitigate CVE-2019-0938, ensure that Microsoft Edge is updated to the latest version.
CVE-2019-0938 affects Microsoft Edge running on various versions of Windows 10 prior to the update.
CVE-2019-0938 does not directly lead to remote code execution but allows elevation of privilege within the system.
CVE-2019-0938 does not affect Microsoft Windows Server 2016 or 2019, as those versions are not vulnerable.