KLA11199
Multiple vulnerabilities in Microsoft Browsers
Updated: 07/22/2020
Detect date
?
02/13/2018
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to obtain sensitive information.
  2. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  3. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
Affected products

Internet Explorer 10
Microsoft Edge (EdgeHTML-based)
ChakraCore
Internet Explorer 11
Internet Explorer 9

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2018-0763
CVE-2018-0771
CVE-2018-0834
CVE-2018-0835
CVE-2018-0836
CVE-2018-0837
CVE-2018-0838
CVE-2018-0839
CVE-2018-0840
CVE-2018-0856
CVE-2018-0857
CVE-2018-0859
CVE-2018-0860
CVE-2018-0861
CVE-2018-0866
CVE-2018-0858

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
CVE-IDS
?
CVE-2018-07630.0Unknown
CVE-2018-07710.0Unknown
CVE-2018-08340.0Unknown
CVE-2018-08350.0Unknown
CVE-2018-08360.0Unknown
CVE-2018-08370.0Unknown
CVE-2018-08380.0Unknown
CVE-2018-08390.0Unknown
CVE-2018-08400.0Unknown
CVE-2018-08560.0Unknown
CVE-2018-08570.0Unknown
CVE-2018-08590.0Unknown
CVE-2018-08600.0Unknown
CVE-2018-08610.0Unknown
CVE-2018-08660.0Unknown
CVE-2018-08580.0Unknown
Microsoft official advisories
Microsoft Security Update Guide
KB list

4074591
4074590
4088776
4074598
4074594
4074593
4074596
4074592
4074588
4074736
4530684

Exploitation

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/44078

https://www.exploit-db.com/exploits/44079

https://www.exploit-db.com/exploits/44081

https://www.exploit-db.com/exploits/44080

https://www.exploit-db.com/exploits/44077

https://www.exploit-db.com/exploits/44076

https://www.exploit-db.com/exploits/44153