← back
CVE-2019-1426

CVE-2019-1426

EPSS 9.4%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 9.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Nov 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1427, CVE-2019-1428, CVE-2019-1429.
Affected products
Microsoft · ChakraCoreMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for ARM64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for ARM64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for 32-bit SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for ARM64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for x64-based SystemsMicrosoft · Microsoft Edge (EdgeHTML-based) on Windows Server 2016Microsoft · Microsoft Edge (EdgeHTML-based) on Windows Server 2019