KLA11199
Multiple vulnerabilities in Microsoft Browsers
Обновлено: 22/07/2020
Дата обнаружения
13/02/2018
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to obtain sensitive information.
  2. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  3. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
Пораженные продукты

Internet Explorer 10
Microsoft Edge (EdgeHTML-based)
ChakraCore
Internet Explorer 11
Internet Explorer 9

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-0763
CVE-2018-0771
CVE-2018-0834
CVE-2018-0835
CVE-2018-0836
CVE-2018-0837
CVE-2018-0838
CVE-2018-0839
CVE-2018-0840
CVE-2018-0856
CVE-2018-0857
CVE-2018-0859
CVE-2018-0860
CVE-2018-0861
CVE-2018-0866
CVE-2018-0858
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Связанные продукты
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
CVE-IDS
CVE-2018-07630.0Unknown
CVE-2018-07710.0Unknown
CVE-2018-08340.0Unknown
CVE-2018-08350.0Unknown
CVE-2018-08360.0Unknown
CVE-2018-08370.0Unknown
CVE-2018-08380.0Unknown
CVE-2018-08390.0Unknown
CVE-2018-08400.0Unknown
CVE-2018-08560.0Unknown
CVE-2018-08570.0Unknown
CVE-2018-08590.0Unknown
CVE-2018-08600.0Unknown
CVE-2018-08610.0Unknown
CVE-2018-08660.0Unknown
CVE-2018-08580.0Unknown
Microsoft official advisories
Microsoft Security Update Guide
KB list

4074591
4074590
4088776
4074598
4074594
4074593
4074596
4074592
4074588
4074736
4530684

Эксплуатация

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/44078

https://www.exploit-db.com/exploits/44079

https://www.exploit-db.com/exploits/44081

https://www.exploit-db.com/exploits/44080

https://www.exploit-db.com/exploits/44077

https://www.exploit-db.com/exploits/44076

https://www.exploit-db.com/exploits/44153