KLA11199
Multiple vulnerabilities in Microsoft Browsers

Обновлено: 05/05/2022
Дата обнаружения
13/02/2018
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to obtain sensitive information.
  2. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  3. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
Пораженные продукты

Internet Explorer 10
Microsoft Edge (EdgeHTML-based)
ChakraCore
Internet Explorer 11
Internet Explorer 9

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-0763
CVE-2018-0771
CVE-2018-0834
CVE-2018-0835
CVE-2018-0836
CVE-2018-0837
CVE-2018-0838
CVE-2018-0839
CVE-2018-0840
CVE-2018-0856
CVE-2018-0857
CVE-2018-0859
CVE-2018-0860
CVE-2018-0861
CVE-2018-0866
CVE-2018-0858
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Связанные продукты
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
CVE-IDS
CVE-2018-07632.6Warning
CVE-2018-07714.3Warning
CVE-2018-08349.3Critical
CVE-2018-08357.6Critical
CVE-2018-08367.6Critical
CVE-2018-08377.6Critical
CVE-2018-08387.6Critical
CVE-2018-08394.3Warning
CVE-2018-08409.3Critical
CVE-2018-08567.6Critical
CVE-2018-08577.6Critical
CVE-2018-08597.6Critical
CVE-2018-08607.6Critical
CVE-2018-08619.3Critical
CVE-2018-08669.3Critical
CVE-2018-08589.3Critical