Kaspersky ID:
KLA10967
Дата обнаружения:
14/03/2017
Обновлено:
22/07/2020

Описание

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Browser can be exploited remotely via specially crafted content to obtain sensitive information.
  2. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  3. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
  5. A spoofing vulnerability in Microsoft Browser can be exploited remotely via specially crafted website to spoof user interface.
  6. A memory corruption vulnerability in Microsoft Browser can be exploited remotely via specially crafted website to execute arbitrary code.
  7. An information disclosure vulnerability in Scripting Engine can be exploited remotely via specially crafted content to execute arbitrary code.
  8. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  9. A remote code execution vulnerability in Windows PDF can be exploited remotely via specially crafted website to execute arbitrary code.
  10. An information disclosure vulnerability in Internet Explorer can be exploited remotely via specially crafted content to obtain sensitive information.
  11. An elevation of privilege vulnerability in Internet Explorer can be exploited remotely via specially crafted content to obtain sensitive information.

Первичный источник обнаружения

Эксплуатация

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/41623

https://www.exploit-db.com/exploits/43125

https://www.exploit-db.com/exploits/41454

https://www.exploit-db.com/exploits/42354

https://www.exploit-db.com/exploits/43125

https://www.exploit-db.com/exploits/41661

Связанные продукты

Список CVE

  • CVE-2017-0065
    unknown
  • CVE-2017-0066
    unknown
  • CVE-2017-0067
    unknown
  • CVE-2017-0068
    unknown
  • CVE-2017-0069
    unknown
  • CVE-2017-0070
    unknown
  • CVE-2017-0071
    unknown
  • CVE-2017-0094
    unknown
  • CVE-2017-0037
    unknown
  • CVE-2017-0131
    unknown
  • CVE-2017-0132
    unknown
  • CVE-2017-0133
    unknown
  • CVE-2017-0134
    unknown
  • CVE-2017-0135
    unknown
  • CVE-2017-0136
    unknown
  • CVE-2017-0137
    unknown
  • CVE-2017-0138
    unknown
  • CVE-2017-0140
    unknown
  • CVE-2017-0141
    unknown
  • CVE-2017-0150
    unknown
  • CVE-2017-0151
    unknown
  • CVE-2017-0009
    unknown
  • CVE-2017-0010
    unknown
  • CVE-2017-0011
    unknown
  • CVE-2017-0012
    unknown
  • CVE-2017-0015
    unknown
  • CVE-2017-0017
    unknown
  • CVE-2017-0023
    unknown
  • CVE-2017-0032
    unknown
  • CVE-2017-0033
    unknown
  • CVE-2017-0034
    unknown
  • CVE-2017-0035
    unknown
  • CVE-2017-0049
    unknown
  • CVE-2017-0059
    unknown
  • CVE-2017-0130
    unknown
  • CVE-2017-0149
    unknown
  • CVE-2017-0154
    unknown
  • CVE-2017-0008
    unknown
  • CVE-2017-0018
    unknown
  • CVE-2017-0040
    unknown

Список KB

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Confirm changes?
Your message has been sent successfully.