Searching
..

Click anywhere to stop

KLA11265
Multiple vulnerabilities in Microsoft Internet Explorer & Edge

Обновлено: 22/01/2024
Дата обнаружения
12/06/2018
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A security feature bypass vulnerability in Internet Explorer can be exploited remotely via specially crafted to bypass security restrictions.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
  5. A memory corruption vulnerability in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  6. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  7. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  8. An information disclosure vulnerability in Microsoft Edge can be exploited remotely to obtain sensitive information.
  9. A memory corruption vulnerability in ChakraCore can be exploited remotely to execute arbitrary code.

Technical details

Vulnerability (4) allows to bypass Mark of the Web Tagging (MOTW).

Пораженные продукты

Internet Explorer 10
Internet Explorer 11
Internet Explorer 9
ChakraCore
Microsoft Edge (EdgeHTML-based)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-8227
CVE-2018-8229
CVE-2018-8236
CVE-2018-8113
CVE-2018-8234
CVE-2018-8249
CVE-2018-8110
CVE-2018-8235
CVE-2018-8267
CVE-2018-0871
CVE-2018-8111
CVE-2018-0978
CVE-2018-8243
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

SUI 
[?]
Связанные продукты
Microsoft Internet Explorer
Microsoft Edge
ChakraCore
CVE-IDS
CVE-2018-82277.6Critical
CVE-2018-82297.6Critical
CVE-2018-82437.6Critical
CVE-2018-82367.6Critical
CVE-2018-81134.3Warning
CVE-2018-82344.3Warning
CVE-2018-82497.6Critical
CVE-2018-81107.6Critical
CVE-2018-82354.3Warning
CVE-2018-82677.6Critical
CVE-2018-08714.3Warning
CVE-2018-81117.6Critical
CVE-2018-09787.6Critical