SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-8720

WebKitGTK Memory Corruption Vulnerability

KEVHIGH 8.8EPSS 1.56%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.56% probability · 74th percentile
CISA KEV
Listed 23 May 2022 · due 13 June 2022
Weakness
CWE-119
Affected
webkitgtk/webkitgtk · wpewebkit/wpe webkit · redhat/codeready linux builder · redhat/codeready linux builder eus · redhat/codeready linux builder for arm64 eus · redhat/codeready linux builder for ibm z systems eus · redhat/codeready linux builder for power little endian eus · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux for arm64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server for power little endian update services for sap solutions · +3 more
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-8720

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.