CVE-2020-0813: High severity chakracore vulnerability
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory., aka 'Scripting Engine Information Disclosure Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-0813?
CVE-2020-0813 is an information disclosure vulnerability in Microsoft ChakraCore and Microsoft Edge that allows an attacker to access the contents of memory, potentially leading to further compromise of the computer or data.
How does CVE-2020-0813 work?
CVE-2020-0813 can be exploited when Chakra improperly discloses the contents of its memory, which requires the attacker to know the memory address of the targeted object.
What is the severity of CVE-2020-0813?
CVE-2020-0813 has a severity rating of 7.5 (high).
Which software is affected by CVE-2020-0813?
CVE-2020-0813 affects Microsoft ChakraCore and Microsoft Edge.
How can I fix CVE-2020-0813?
To fix CVE-2020-0813, update to the latest version of Microsoft ChakraCore or Microsoft Edge.