CVE-2019-1141 is a remote code execution vulnerability in the Chakra scripting engine affecting Microsoft Edge (HTML-based) on Windows 10 and Windows Server 2019. It allows an attacker to execute arbitrary code with the current user's privileges by convincing them to visit a specially crafted website. The vulnerability has a CVSS score of 4.2 (Medium) due to its high attack complexity and user interaction requirement, but could lead to full system compromise if the user has administrative rights. There is no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal, suggesting low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.