HIGH
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'
Published Mar 6, 2019
8.1
HIGHCVSS 3.0
EPSS 4.35%
Description
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
Affected products
-
- Version unspecifiedStatusaffectedConstraints-
- Version
-
- Version Windows 10 Version 1703 for 32-bit SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1703 for x64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1709 for 32-bit SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1709 for ARM64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1709 for x64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1803 for 32-bit SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1803 for ARM64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1803 for x64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1809 for 32-bit SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1809 for ARM64-based SystemsStatusaffectedConstraints-
- Version Windows 10 Version 1809 for x64-based SystemsStatusaffectedConstraints-
- Version Windows Server 2019StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | ChakraCore | n/a |
| |||||||||||||||||||||||||||||||||||||||
| Microsoft | Microsoft Edge | n/a |
|
Configuration 1
AND
Running on/with
OR
- n/a
- 1703
- 1709
- 1803
- 1809
- n/a
Configuration 2
- < 1.11.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (7)
- http://www.securityfocus.com/bid/106877 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-6c6r-39cv-x5fq Advisory
- https://github.com/chakra-core/ChakraCore/commit/beba75a1aed0933cf3c76efb4dc67529dc035901
- https://github.com/chakra-core/ChakraCore/pull/5936
- https://nvd.nist.gov/vuln/detail/CVE-2019-0649
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0649 x_refsource_CONFIRMPatchVendor Advisory
- https://web.archive.org/web/20210125001406/https://www.securityfocus.com/bid/106877/
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106877 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/advisories/GHSA-6c6r-39cv-x5fq | Advisory | |
| https://github.com/chakra-core/ChakraCore/commit/beba75a1aed0933cf3c76efb4dc67529dc035901 | ||
| https://github.com/chakra-core/ChakraCore/pull/5936 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-0649 | ||
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0649 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://web.archive.org/web/20210125001406/https://www.securityfocus.com/bid/106877/ |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Mar 6, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
Link CVE-2019-0649
CISA Vulnrichment
GHSA-6C6R-39CV-X5FQ Updated n/a