KLA11397
Multiple vulnerabilities in Microsoft Browsers
Updated: 01/14/2019
Detect date
?
01/08/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A remote code execution vulnerability in MSHTML Engine can be exploited remotely via specially crafted file to execute arbitrary code.
  4. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  5. An elevation of privilege vulnerability in Microsoft Edge can be exploited remotely via unspecified vector to gain privileges.
  6. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
Affected products

Microsoft Edge
ChakraCore
Microsoft Office 2016 (64-bit edition)
Internet Explorer 11
Office 365 ProPlus for 32-bit Systems
Microsoft Office Word Viewer
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Internet Explorer 10
Microsoft Office 2013 RT Service Pack 1
Microsoft Office 2016 (32-bit edition)
Office 365 ProPlus for 64-bit Systems
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Internet Explorer 9
Microsoft Excel Viewer 2007 Service Pack 3

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-0565
CVE-2019-0567
CVE-2019-0541
CVE-2019-0568
CVE-2019-0566
CVE-2019-0539

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
?

CVE-2019-0541
CVE-2019-0565
CVE-2019-0567
CVE-2019-0568
CVE-2019-0566
CVE-2019-0539

KB list

4480978
4480962
4480966
4480116
4480961
4480973
4480963
4480968
4480970
4480975
4480965

Microsoft official advisories
Microsoft Security Update Guide