KLA11290
Multiple vulnerabilities in Microsoft Edge and Internet Explorer
Updated: 11/06/2018
CVSS
?
7.5
Detect date
?
07/10/2018
Severity
?
Critical
Description

Multiple serious vulnerabilities were found in Microsoft Internet Explorer and Edge. Malicious users can exploit these vulnerabilities to bypass security restrictions, spoof user interface, execute arbitrary code and obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A security feature bypass vulnerability in Microsoft Internet Explorer can be exploited remotely via specially crafted website to bypass security restrictions;
  2. A spoofing vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to spoof user interface;
  3. A remote code execution vulnerabilities in Microsoft Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code;
  4. A remote code execution vulnerabilities in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code;
  5. An information disclosure vulnerabilities in Microsoft Edge can be exploited remotely via website with specially crafted content in user-provided content to obtain sensitive information;
  6. A security feature bypass vulnerability in the Microsoft Edge can be exploited remotely to bypass security restrictions;
  7. A remote code execution vulnerabilities in Microsoft Internet Explorer and Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code;
Affected products

Internet Explorer 10
Internet Explorer 11
Internet Explorer 9
Microsoft Edge

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2018-0949
CVE-2018-8278
CVE-2018-8242
CVE-2018-8286
CVE-2018-8279
CVE-2018-8324
CVE-2018-8294
CVE-2018-8296
CVE-2018-8297
CVE-2018-8262
CVE-2018-8125
CVE-2018-8276
CVE-2018-8280
CVE-2018-8290
CVE-2018-8274
CVE-2018-8325
CVE-2018-8301
CVE-2018-8289
CVE-2018-8288
CVE-2018-8291
CVE-2018-8275
CVE-2018-8287

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
?

CVE-2018-0949
CVE-2018-8278
CVE-2018-8242
CVE-2018-8286
CVE-2018-8279
CVE-2018-8324
CVE-2018-8294
CVE-2018-8296
CVE-2018-8297
CVE-2018-8262
CVE-2018-8125
CVE-2018-8276
CVE-2018-8280
CVE-2018-8290
CVE-2018-8274
CVE-2018-8325
CVE-2018-8301
CVE-2018-8289
CVE-2018-8288
CVE-2018-8291
CVE-2018-8275
CVE-2018-8287

Microsoft official advisories
Microsoft Security Update Guide
KB list

4338830
4338815
4338825
4338814
4338818
4338829
4338819
4338826
4345421
4345419
4338816
4345455
4338831
4345459
4345420
4345424
4338821
4345425
4345418
4339093