cbcvebase.
CVE-2019-0648
published 2019-03-05

CVE-2019-0648: An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to…

PriorityP423medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
5.43%
91.9th percentile
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory, aka Scripting Engine Information Disclosure Vulnerability. This CVE ID is unique from CVE-2019-0658.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftchakracore< 1.11.61.11.6
microsoftchakracore
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcmicrosoft_edge_on_windows_10_version_1809_for_32-bit_systems
msrcmicrosoft_edge_on_windows_10_version_1809_for_arm64-based_systems
msrcmicrosoft_edge_on_windows_10_version_1809_for_x64-based_systems
msrcmicrosoft_edge_on_windows_server_2019

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.