VYPR
High severityNVD Advisory· Published Aug 14, 2019· Updated Aug 4, 2024

Chakra Scripting Engine Memory Corruption Vulnerability

CVE-2019-1140

Description

A remote code execution vulnerability in Microsoft Edge's Chakra scripting engine allows an attacker to execute arbitrary code via a specially crafted website.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote code execution vulnerability in Microsoft Edge's Chakra scripting engine allows an attacker to execute arbitrary code via a specially crafted website.

Vulnerability

The vulnerability is a remote code execution issue in the Chakra scripting engine used by Microsoft Edge (HTML-based). It exists in the way Chakra handles objects in memory, leading to memory corruption that an attacker can exploit to execute arbitrary code [1].

Exploitation

In a web-based attack scenario, an attacker can host a specially crafted website designed to trigger the vulnerability through Edge. The attacker then convinces a user to view the website, or leverages compromised sites that host user-provided content or advertisements. No authentication is required, as the attacker only needs to get the user to visit the malicious page [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. If that user has administrative rights, the attacker can gain full control of the system, install programs, view/change/delete data, or create new accounts with full user rights [1].

Mitigation

Microsoft released a security update that addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. Users should apply the update to mitigate the risk [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.ChakraCoreNuGet
< 1.11.121.11.12

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.