CVE-2019-0649
published 2019-03-05CVE-2019-0649: A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
PriorityP343high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
4.36%
90.2th percentile
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chakracore | < 1.11.6 | 1.11.6 |
| microsoft | chakracore | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| msrc | chakracore | — | — |
| msrc | microsoft_edge_on_windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_arm64-based_systems | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Edge/ChakraCore Scripting Engine access control (EUVD-2022-2768 / ID 91502)
vuldb·2026-04-28·CVSS 8.1
CVE-2019-0649 [HIGH] Microsoft Edge/ChakraCore Scripting Engine access control (EUVD-2022-2768 / ID 91502)
A vulnerability categorized as critical has been discovered in Microsoft Edge and ChakraCore. This impacts an unknown function of the component Scripting Engine. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2019-0649. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
OSV
Chakra JIT server Privilege Escalation
osv·2022-05-13
CVE-2019-0649 [HIGH] Chakra JIT server Privilege Escalation
Chakra JIT server Privilege Escalation
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileges Vulnerability'.
GHSA
Chakra JIT server Privilege Escalation
ghsa·2022-05-13
CVE-2019-0649 [HIGH] Chakra JIT server Privilege Escalation
Chakra JIT server Privilege Escalation
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileges Vulnerability'.
Microsoft
Scripting Engine Elevation of Privileged Vulnerability
vendor_msrc·2019-02-12·CVSS 4.2
CVE-2019-0649 [HIGH] Scripting Engine Elevation of Privileged Vulnerability
Scripting Engine Elevation of Privileged Vulnerability
Description: A vulnerability exists in Microsoft Chakra JIT server. An attacker who successfully exploited this vulnerability could gain elevated privileges.
The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running.
The security update addresses the vulnerability by modifying how Microsoft Chakra handles constructorCaches.
Microsoft Scripting Engine: Microsoft Scripting Engine
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Relea
Suricata
GPL SQL Slammer Worm propagation attempt
suricata·2010-09-23
CVE-2002-0649 GPL SQL Slammer Worm propagation attempt
GPL SQL Slammer Worm propagation attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 1434 (msg:"GPL SQL Slammer Worm propagation attempt"; content:"|04|"; depth:1; content:"|81 F1 03 01 04 9B 81 F1 01|"; content:"sock"; content:"send"; reference:bugtraq,5310; reference:bugtraq,5311; reference:cve,2002-0649; reference:nessus,11214; reference:url,vil.nai.com/vil/content/v_99992.htm; classtype:misc-attack; sid:2102003; rev:9; metadata:created_at 2010_09_23, cve CVE_2002_0649, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
Suricata
GPL WORM Slammer Worm propagation attempt OUTBOUND
suricata·2010-09-23
CVE-2002-0649 GPL WORM Slammer Worm propagation attempt OUTBOUND
GPL WORM Slammer Worm propagation attempt OUTBOUND
Rule: alert udp $HOME_NET any -> $EXTERNAL_NET 1434 (msg:"GPL WORM Slammer Worm propagation attempt OUTBOUND"; content:"|04|"; depth:1; content:"|81 F1 03 01 04 9B 81 F1|"; content:"sock"; content:"send"; reference:bugtraq,5310; reference:bugtraq,5311; reference:cve,2002-0649; reference:nessus,11214; reference:url,vil.nai.com/vil/content/v_99992.htm; classtype:misc-attack; sid:2102004; rev:8; metadata:created_at 2010_09_23, cve CVE_2002_0649, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
No public exploits indexed.
No writeups or analysis indexed.
2019-03-05
Published