Beschreibung
Multiple serious vulnerabilities have been found in Microsoft Internet Explorer and Edge. Malicious users can exploit these vulnerabilities to execute arbitrary code or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper memory objects handling can be exploited remotely via a specially designed content to execute arbitrary code or obtain sensitive information;
- An improper page content handling can be exploited remotely via a specially designed content to obtain sensitive information;
- An improper memory objects handling at Chakra JavaScript engine can be exploited remotely via a specially designed content to execute arbitrary code.
Technical details
To mitigate vulnerability №1 remove Microsoft EDGE from the PDF reader default file type association
To exploit vulnerability №2 an attacker must have valid logon credentials and be able to log on locally
Ursprüngliche Informationshinweise
- CVE-2016-3321
- CVE-2016-3319
- CVE-2016-3296
- CVE-2016-3293
- CVE-2016-3290
- CVE-2016-3289
- CVE-2016-3288
- CVE-2016-3329
- CVE-2016-3327
- CVE-2016-3326
CVE Liste
- CVE-2016-3322 high
- CVE-2016-3321 high
- CVE-2016-3319 high
- CVE-2016-3296 high
- CVE-2016-3293 high
- CVE-2016-3290 high
- CVE-2016-3289 high
- CVE-2016-3288 high
- CVE-2016-3329 high
- CVE-2016-3327 high
- CVE-2016-3326 high
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!