Information disclosure in Microsoft Edge - CVE-2019-0658

 

Information disclosure in Microsoft Edge - CVE-2019-0658

Published: February 12, 2019


Vulnerability identifier: #VU17583
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0658
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to an error when the scripting engine does not properly handle objects in memory in Microsoft Edge. A remote attacker can trick the victim into visiting a specially crafted website and gain access to arbitrary data.


Affected software

Microsoft Edge
ChakraCore

How to mitigate CVE-2019-0658

Install updates from vendor's website.


External References

Related Security Bulletins