KLA11112
Multiple vulnerabilities in Microsoft Browsers
Updated: 07/22/2020
Detect date
?
10/10/2017
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  3. An information disclosure vulnerability in Internet Explorer can be exploited remotely via specially crafted content to obtain sensitive information.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
  5. A memory corruption vulnerability in Scripting Engine can be exploited remotely to execute arbitrary code.
Affected products

Microsoft Edge (EdgeHTML-based)
Internet Explorer 9
Internet Explorer 10
ChakraCore
Internet Explorer 11

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2017-11810
CVE-2017-11811
CVE-2017-11812
CVE-2017-11813
CVE-2017-11790
CVE-2017-11792
CVE-2017-11793
CVE-2017-11794
CVE-2017-11796
CVE-2017-11798
CVE-2017-11800
CVE-2017-11805
CVE-2017-11808
CVE-2017-11804
CVE-2017-11809
CVE-2017-11799
CVE-2017-11822
CVE-2017-11806
CVE-2017-11802
CVE-2017-11807
CVE-2017-8726
CVE-2017-11821
CVE-2017-11797
CVE-2017-11801

Impacts
?
ACE 
[?]

OSI 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
?
CVE-2017-117970.0Unknown
CVE-2017-118010.0Unknown
CVE-2017-118100.0Unknown
CVE-2017-118110.0Unknown
CVE-2017-118120.0Unknown
CVE-2017-118130.0Unknown
CVE-2017-117900.0Unknown
CVE-2017-117920.0Unknown
CVE-2017-117930.0Unknown
CVE-2017-117940.0Unknown
CVE-2017-117960.0Unknown
CVE-2017-117980.0Unknown
CVE-2017-118000.0Unknown
CVE-2017-118050.0Unknown
CVE-2017-118080.0Unknown
CVE-2017-118040.0Unknown
CVE-2017-118090.0Unknown
CVE-2017-117990.0Unknown
CVE-2017-118220.0Unknown
CVE-2017-118060.0Unknown
CVE-2017-118020.0Unknown
CVE-2017-118070.0Unknown
CVE-2017-87260.0Unknown
CVE-2017-118210.0Unknown
Microsoft official advisories
Microsoft Security Update Guide
KB list

4041689
4041693
4041676
4041690
4041681
4041691
4042895
4040685

Exploitation

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/43131

https://www.exploit-db.com/exploits/43152

https://www.exploit-db.com/exploits/43368

https://www.exploit-db.com/exploits/42999

https://www.exploit-db.com/exploits/42998

https://www.exploit-db.com/exploits/43000