KLA11557
Multiple vulnerabilities in Microsoft Browsers

Updated: 07/22/2020
Detect date
?
09/10/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code;
  2. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information;
  3. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code;
  4. A security feature bypass vulnerability in Microsoft Browser can be exploited remotely via specially crafted to bypass security restrictions;
  5. A remote code execution vulnerability in VBScript can be exploited remotely via specially crafted website to execute arbitrary code.
Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Affected products

ChakraCore
Microsoft Edge (EdgeHTML-based)
Internet Explorer 11
Internet Explorer 9
Internet Explorer 10

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-1300
CVE-2019-1299
CVE-2019-1138
CVE-2019-1237
CVE-2019-1217
CVE-2019-1221
CVE-2019-1220
CVE-2019-1236
CVE-2019-1208
CVE-2019-1298

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Related products
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
?
CVE-2019-11387.6Critical
CVE-2019-12987.6Critical
CVE-2019-12377.6Critical
CVE-2019-13007.6Critical
CVE-2019-12177.6Critical
CVE-2019-12994.3Warning
CVE-2019-12217.6Critical
CVE-2019-12204.3Warning
CVE-2019-12367.6Critical
CVE-2019-12087.6Critical
Microsoft official advisories
Microsoft Security Update Guide
KB list

4516066
4516068
4516065
4515384
4516044
4512578
4516058
4516067
4516055
4516070
4516046

Find out the statistics of the vulnerabilities spreading in your region