Lucene search

K
cve[email protected]CVE-2019-1030
HistoryAug 14, 2019 - 9:15 p.m.

CVE-2019-1030

2019-08-1421:15:13
CWE-200
web.nvd.nist.gov
47
microsoft edge
information disclosure
vulnerability
cve-2019-1030
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.2%

An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker’s site.
The update addresses the vulnerability by modifying how Microsoft Edge based on Edge HTML handles objects in memory.

Affected configurations

Vulners
NVD
Node
microsoftedgeMatch1.0..0
VendorProductVersionCPE
microsoftedgeWindows 10 for 32-bit Systemscpe:2.3:a:microsoft:edge:Windows 10 for 32-bit Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 for x64-based Systemscpe:2.3:a:microsoft:edge:Windows 10 for x64-based Systems:*:*:*:*:*:*:*
microsoftedgeWindows Server 2016cpe:2.3:a:microsoft:edge:Windows Server 2016:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1607 for 32-bit Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1607 for 32-bit Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1607 for x64-based Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1607 for x64-based Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1703 for 32-bit Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1703 for 32-bit Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1703 for x64-based Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1703 for x64-based Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1709 for 32-bit Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1709 for 32-bit Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1709 for x64-based Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1709 for x64-based Systems:*:*:*:*:*:*:*
microsoftedgeWindows 10 Version 1803 for 32-bit Systemscpe:2.3:a:microsoft:edge:Windows 10 Version 1803 for 32-bit Systems:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Microsoft Edge (EdgeHTML-based)",
    "cpes": [
      "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Windows 10 Version 1703 for 32-bit Systems",
      "Windows 10 Version 1703 for x64-based Systems",
      "Windows 10 Version 1803 for 32-bit Systems",
      "Windows 10 Version 1803 for x64-based Systems",
      "Windows 10 Version 1803 for ARM64-based Systems",
      "Windows 10 Version 1809 for 32-bit Systems",
      "Windows 10 Version 1809 for x64-based Systems",
      "Windows 10 Version 1809 for ARM64-based Systems",
      "Windows Server 2019",
      "Windows 10 Version 1709 for 32-bit Systems",
      "Windows 10 Version 1709 for x64-based Systems",
      "Windows 10 Version 1709 for ARM64-based Systems",
      "Windows 10 Version 1903 for 32-bit Systems",
      "Windows 10 Version 1903 for x64-based Systems",
      "Windows 10 Version 1903 for ARM64-based Systems",
      "Windows 10 for 32-bit Systems",
      "Windows 10 for x64-based Systems",
      "Windows 10 Version 1607 for 32-bit Systems",
      "Windows 10 Version 1607 for x64-based Systems",
      "Windows Server 2016"
    ],
    "versions": [
      {
        "version": "1.0..0",
        "lessThan": "publication",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.2%