KLA10968
Multiple vulnerabilities in Microsoft Edge
Обновлено: 17/06/2019
Дата обнаружения
14/03/2017
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in Microsoft Edge. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, obtain sensitive information and bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An incorrect handling of objects in memory done by JScript and VBScript while rendering can be exploited remotely via a specially designed website or Microsoft Office document that hosts the IE engine to execute arbitrary code and gain privileges;
  2. An improper handling of objects in memory done by affected components can be exploited remotely via specially designed content to obtain sensitive information;
  3. An inaccurate parsing of HTTP responses can be exploited remotely via a specially designed website to spoof content or trigger another attack in web services;
  4. A type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll can be exploited remotely via vectors involving a specially designed CSS token sequence and specially designed JavaScript code working with a TH element to execute arbitrary code and possibly to cause a denial of service;
  5. An improper handling of objects in memory done by Microsoft Windows PDF can be exploited remotely via a specially designed website with malicious PDF content to execute arbitrary code;
  6. A failure in applying Same Origin Policy for HTML elements present in the other browser windows can be exploited remotely via a specially designed webpage or website to bypass security restrictions;
  7. An improper access to the objects in memorry can be exploited remotely via a specially designed website to execute arbitrary code.
Пораженные продукты

Microsoft Edge

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
MS17-007
CVE-2017-0065
CVE-2017-0066
CVE-2017-0067
CVE-2017-0068
CVE-2017-0069
CVE-2017-0070
CVE-2017-0071
CVE-2017-0094
CVE-2017-0037
CVE-2017-0131
CVE-2017-0132
CVE-2017-0133
CVE-2017-0134
CVE-2017-0135
CVE-2017-0136
CVE-2017-0137
CVE-2017-0138
CVE-2017-0140
CVE-2017-0141
CVE-2017-0150
CVE-2017-0151
CVE-2017-0009
CVE-2017-0010
CVE-2017-0011
CVE-2017-0012
CVE-2017-0015
CVE-2017-0017
CVE-2017-0023
CVE-2017-0032
CVE-2017-0033
CVE-2017-0034
CVE-2017-0035
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Edge
CVE-IDS
CVE-2017-00654.3Warning
CVE-2017-00664.0Warning
CVE-2017-00677.6Critical
CVE-2017-00684.3Warning
CVE-2017-00694.3Warning
CVE-2017-00707.6Critical
CVE-2017-00717.6Critical
CVE-2017-00947.6Critical
CVE-2017-00377.6Critical
CVE-2017-01317.6Critical
CVE-2017-01327.6Critical
CVE-2017-01337.6Critical
CVE-2017-01347.6Critical
CVE-2017-01354.0Warning
CVE-2017-01367.6Critical
CVE-2017-01377.6Critical
CVE-2017-01387.6Critical
CVE-2017-01404.0Warning
CVE-2017-01417.6Critical
CVE-2017-01507.6Critical
CVE-2017-01517.6Critical
CVE-2017-00094.3Warning
CVE-2017-00107.6Critical
CVE-2017-00114.3Warning
CVE-2017-00124.3Warning
CVE-2017-00157.6Critical
CVE-2017-00174.3Warning
CVE-2017-00237.6Critical
CVE-2017-00327.6Critical
CVE-2017-00334.3Warning
CVE-2017-00347.6Critical
CVE-2017-00357.6Critical
Microsoft official advisories
Microsoft Security Update Guide
KB list

4012606
4013198
4013429
4013071