CVE-2019-1429
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
Affected (3)
Products: Microsoft: Internet Explorer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 1507 | All versions |
Microsoft Windows 10 1607 | All versions |
Microsoft Windows 10 1709 | All versions |
Microsoft Windows 10 1803 | All versions |
Microsoft Windows 10 1809 | All versions |
Microsoft Windows 10 1903 | All versions |
Microsoft Windows 7 | All versions |
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Server 2012 | All versions |
Microsoft Windows Server 2016 | All versions |
Microsoft Windows Server 2019 | All versions |
Related CWEs
CWE-416
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (5)
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.