ZeroHour

CVE-2019-8720

KEVmass

Memory Corruption in WebKitGTK/WPE WebKit Enables Arbitrary Code Execution

CISA: WebKitGTK Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
KEV added
AI analysis

CVE-2019-8720 is a memory corruption flaw (CWE-119) in the WebKit engine as packaged in WebKitGTK and WPE WebKit, in which multiple memory-handling errors can be triggered by processing maliciously crafted web content. An attacker who gets a user to load attacker-controlled HTML — for example through an application that uses WebKitGTK to render email, feeds, or other web content — can corrupt memory and potentially execute arbitrary code with the privileges of that application. The CVSS 3.1 score of 8.8 (high) reflects that the attack path is network-based, requires no privileges but does require user interaction, and yields high impact on confidentiality, integrity, and availability. Users of WebKitGTK and WPE WebKit, including the packages shipped with Red Hat Enterprise Linux and its desktop, EUS, and architecture-specific variants, are affected. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 1.6% probability of exploitation in the next 30 days.

What to do: Apply updated WebKitGTK/WPE WebKit packages per vendor instructions — for Red Hat Enterprise Linux, install the corrected packages from Red Hat security errata for your release — and prioritize systems where users view untrusted HTML, such as mail, feed, or desktop applications that embed WebKitGTK. As an interim mitigation, avoid rendering untrusted web content in applications that use WebKitGTK. Inventory hosts for webkitgtk/webkit2gtk packages and confirm they are on the patched release for your Red Hat Enterprise Linux version.

Affected
WebKitGTK
WPE WebKit
Red Hat Enterprise Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux EUS
Red Hat Enterprise Linux for ARM64 EUS
Red Hat Enterprise Linux for IBM Z Systems
Red Hat CodeReady Linux Builder
Red Hat CodeReady Linux Builder EUS
Red Hat CodeReady Linux Builder for ARM64 EUS
Red Hat CodeReady Linux Builder for IBM Z Systems EUS
Red Hat CodeReady Linux Builder for POWER Little Endian EUS
Estimated exposure
massplausibly millions of Linux installations (WebKitGTK ships within Red Hat Enterprise Linux and GNOME desktop stacks) — WebKitGTK is bundled with Red Hat Enterprise Linux, whose installed base is measured in the millions of systems, though practically exploitable hosts are those where users render untrusted web content through applications embedding…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CISA Known Exploited Vulnerability
Affected
WebKitGTK WebKitGTK
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
webkitgtkwpewebkitredhat
Products
webkitgtk, wpe webkit, codeready linux builder, codeready linux builder eus, codeready linux builder for arm64 eus, codeready linux builder for ibm z systems eus, codeready linux builder for power little endian eus, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux for arm64 eus, enterprise linux for ibm z systems
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.