KLA11265
Multiple vulnerabilities in Microsoft Internet Explorer & Edge
Updated: 06/18/2020
Detect date
?
06/12/2018
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A security feature bypass vulnerability in Internet Explorer can be exploited remotely via specially crafted to bypass security restrictions.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
  5. A memory corruption vulnerability in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  6. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  7. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  8. An information disclosure vulnerability in Microsoft Edge can be exploited remotely to obtain sensitive information.
  9. A memory corruption vulnerability in ChakraCore can be exploited remotely to execute arbitrary code.

Technical details

Vulnerability (4) allows to bypass Mark of the Web Tagging (MOTW).

Affected products

Internet Explorer 10
Internet Explorer 11
Internet Explorer 9
ChakraCore
Microsoft Edge (EdgeHTML-based)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2018-8227
CVE-2018-8229
CVE-2018-8236
CVE-2018-8113
CVE-2018-8234
CVE-2018-8249
CVE-2018-8110
CVE-2018-8235
CVE-2018-8267
CVE-2018-0871
CVE-2018-8111
CVE-2018-0978
CVE-2018-8243

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
CVE-IDS
?
CVE-2018-82270.0Unknown
CVE-2018-82290.0Unknown
CVE-2018-82430.0Unknown
CVE-2018-82360.0Unknown
CVE-2018-81130.0Unknown
CVE-2018-82340.0Unknown
CVE-2018-82490.0Unknown
CVE-2018-81100.0Unknown
CVE-2018-82350.0Unknown
CVE-2018-82670.0Unknown
CVE-2018-08710.0Unknown
CVE-2018-81110.0Unknown
CVE-2018-09780.0Unknown
Microsoft official advisories
Microsoft Security Update Guide
KB list

4284860
4284874
4284826
4284835
4284880
4284819
4230450
4284855
4284815
4532693
4532691

Exploitation

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/45013