106420vdb entry
http://www.securityfocus.com/bid/106420 CVE-2019-0568
HIGH
ChakraCore RCE Vulnerability
Record summary
CVE-2019-0568 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0539, CVE-2019-0567.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
ChakraCoreBrowse Microsoft / ChakraCore | CVE List | ChakraCore | affected |
Microsoft EdgeBrowse Microsoft / Microsoft Edge | CVE List | Windows 10 Version 1803 for 32-bit Systems | affected |
| Windows 10 Version 1803 for ARM64-based Systems | affected | ||
| Windows 10 Version 1803 for x64-based Systems | affected | ||
| Windows 10 Version 1809 for 32-bit Systems | affected | ||
| Windows 10 Version 1809 for ARM64-based Systems | affected | ||
| Windows 10 Version 1809 for x64-based Systems | affected | ||
| Windows Server 2019 | affected | ||
Microsoft.ChakraCoreBrowse NuGet / Microsoft.ChakraCore | GitHub Advisory | Before 1.11.5 · Fixed in 1.11.5 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-FreeExploitDB exploitby Google Security ResearchNot analyzed1 file
References
7github.com
https://github.com/chakra-core/ChakraCore github.com
https://github.com/chakra-core/ChakraCore/commit/d73c5f12d9c5cbbf64f59ae04e76a531b3e844b3 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-0568 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0568 web.archive.org
https://web.archive.org/web/20210124231429/https://www.securityfocus.com/bid/106420 46205exploit
https://www.exploit-db.com/exploits/46205