CVE-2019-0746Sensitive Information Exposure in Microsoft Chakracore

Severity
6.5MEDIUMNVD
EPSS
22.5%
top 4.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9

Description

An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5microsoft/microsoft_edgeWindows Server 2012
CVEListV5microsoft/chakracoreWindows 10 for 32-bit Systems
CVEListV5microsoft/internet_explorer_9Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2+1
CVEListV5microsoft/internet_explorer_1019 versions+18

Patches

🔴Vulnerability Details

3
OSV
Microsoft.ChakraCore vulnerable to Exposure of Sensitive Information to an Unauthorized Actor2019-04-09
GHSA
Microsoft.ChakraCore vulnerable to Exposure of Sensitive Information to an Unauthorized Actor2019-04-09
CVEList
CVE-2019-0746: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting2019-04-08

📋Vendor Advisories

1
Microsoft
Scripting Engine Information Disclosure Vulnerability2019-03-12
CVE-2019-0746 — Sensitive Information Exposure | cvebase