Beschreibung
Multiple serious vulnerabilities have been found in Microsoft Internet Explorer and Edge. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper memory objects handling at JScript and VBScript engines can be exploited remotely via a specially designed content to execute arbitrary code;
- An improper code integrity validation at Device Guard can be exploited via a specially designed code to bypass security restrictions;
- An improper memory objects handling can be exploited remotely via a specially designed content to execute arbitrary code;
- An improper access permissions handling can be exploited remotelyvia a specially designed content to obtain sensitive information.
Technical details
Vulnerability (2) related to User Mode Code Integrity component of Device Guard which allows running unsigned malicious code as though it were signed by a trusted source.
To mitigate vulnerability (3) user can restrict access to the VBScript and JScript engines. For further instructions take a look at MS16-051 listed in original advisories section.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2016-0189 high
- CVE-2016-0187 high
- CVE-2016-0194 high
- CVE-2016-0193 high
- CVE-2016-0192 high
- CVE-2016-0191 high
- CVE-2016-0188 high
- CVE-2016-0186 high
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com