KLA11478
Multiple vulnerabilities in Microsoft Browsers

Updated: 06/03/2020
Detect date
?
05/14/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, bypass security restrictions, gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft browsers can be exploited remotely via specially crafted website to execute arbitrary code.
  2. Multiple memory corruption vulnerabilities in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A spoofing vulnerability in Internet Explorer can be exploited remotely via specially crafted website to spoof user interface.
  4. A security feature bypass vulnerability in Internet Explorer can be exploited remotely via specially crafted file to bypass security restrictions.
  5. Multiple memory corruption vulnerabilities in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  6. An elevation of privilege vulnerability in Microsoft Edge can be exploited remotely to gain privileges.
  7. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  8. Multiple memory corruption vulnerabilities in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  9. An information disclosure vulnerability in Internet Explorer can be exploited remotely via specially crafted content to obtain sensitive information.
Affected products

Internet Explorer 11
Internet Explorer 10
Internet Explorer 9
Microsoft Edge

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-0940
CVE-2019-0937
CVE-2019-0924
CVE-2019-0913
CVE-2019-0921
CVE-2019-0995
CVE-2019-0918
CVE-2019-0923
CVE-2019-0912
CVE-2019-0929
CVE-2019-0925
CVE-2019-0915
CVE-2019-0927
CVE-2019-0933
CVE-2019-0916
CVE-2019-0938
CVE-2019-0926
CVE-2019-0914
CVE-2019-0911
CVE-2019-0884
CVE-2019-0930
CVE-2019-0917
CVE-2019-0922

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
?
CVE-2019-09407.6Critical
CVE-2019-09377.6Critical
CVE-2019-09247.6Critical
CVE-2019-09137.6Critical
CVE-2019-09214.3Warning
CVE-2019-09956.8High
CVE-2019-09187.6Critical
CVE-2019-09237.6Critical
CVE-2019-09127.6Critical
CVE-2019-09297.6Critical
CVE-2019-09257.6Critical
CVE-2019-09157.6Critical
CVE-2019-09277.6Critical
CVE-2019-09337.6Critical
CVE-2019-09167.6Critical
CVE-2019-09386.8High
CVE-2019-09267.6Critical
CVE-2019-09147.6Critical
CVE-2019-09117.6Critical
CVE-2019-08847.6Critical
CVE-2019-09304.3Warning
CVE-2019-09177.6Critical
CVE-2019-09227.6Critical
KB list

4499179
4499181
4499164
4499171
4499167
4494441
4497936
4499151
4494440
4499154
4498206

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region