First published: Thu Mar 12 2020(Updated: )
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory., aka 'Scripting Engine Information Disclosure Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ChakraCore | ||
Microsoft Edge | ||
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0813 is an information disclosure vulnerability in Microsoft ChakraCore and Microsoft Edge that allows an attacker to access the contents of memory, potentially leading to further compromise of the computer or data.
CVE-2020-0813 can be exploited when Chakra improperly discloses the contents of its memory, which requires the attacker to know the memory address of the targeted object.
CVE-2020-0813 has a severity rating of 7.5 (high).
CVE-2020-0813 affects Microsoft ChakraCore and Microsoft Edge.
To fix CVE-2020-0813, update to the latest version of Microsoft ChakraCore or Microsoft Edge.