HTTP: Microsoft Window's Edge CVE-2019-0648 Security Bypass

This signature detects attempts to exploit a known vulnerability against Microsoft Window's Edge. A successful attack can lead to Security Bypass.

Extended Description

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory, aka Scripting Engine Information Disclosure Vulnerability. This CVE ID is unique from CVE-2019-0658.

References

CVE: CVE-2019-0648

Short Name
HTTP:STC:EDGE:CVE-2019-0648-SB
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Bypass CVE-2019-0648 Edge Microsoft Security Window's
Release Date
02/12/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
CVSS Score

4.3

Found a potential security threat?