An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory., aka 'Scripting Engine Information Disclosure Vulnerability'.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5437 An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory., aka 'Scripting Engine Information Disclosure Vulnerability'.
Github GHSA Github GHSA GHSA-vvvh-5xrm-pxff ChakraCore information disclosure vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.1031}

epss

{'score': 0.09201}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-04T06:18:03.166Z

Reserved: 2019-11-04T00:00:00

Link: CVE-2020-0813

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-12T16:15:16.687

Modified: 2024-11-21T04:54:15.937

Link: CVE-2020-0813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.