Описание
Scripting Engine Elevation of Privileged Vulnerability
A vulnerability exists in Microsoft Chakra JIT server. An attacker who successfully exploited this vulnerability could gain elevated privileges.
The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running.
The security update addresses the vulnerability by modifying how Microsoft Chakra handles constructorCaches.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| ChakraCore | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for 32-bit Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for x64-based Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for 32-bit Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for x64-based Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for ARM64-based Systems | ||
| Microsoft Edge (EdgeHTML-based) on Windows Server 2019 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
EPSS
4.2 Medium
CVSS3
Связанные уязвимости
A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.
Уязвимость компонента JIT server обработчика JavaScript-сценариев ChakraCore браузера Microsoft Edge, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
EPSS
4.2 Medium
CVSS3