KLA11397
Multiple vulnerabilities in Microsoft Browsers
Обновлено: 26/06/2019
Дата обнаружения
08/01/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A remote code execution vulnerability in MSHTML Engine can be exploited remotely via specially crafted file to execute arbitrary code.
  4. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  5. An elevation of privilege vulnerability in Microsoft Edge can be exploited remotely via unspecified vector to gain privileges.
  6. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
Пораженные продукты

Microsoft Edge
ChakraCore
Microsoft Office 2016 (64-bit edition)
Internet Explorer 11
Office 365 ProPlus for 32-bit Systems
Microsoft Office Word Viewer
Microsoft Office 2019 for 32-bit editions
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Internet Explorer 10
Microsoft Office 2013 RT Service Pack 1
Microsoft Office 2016 (32-bit edition)
Office 365 ProPlus for 64-bit Systems
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Internet Explorer 9
Microsoft Excel Viewer 2007 Service Pack 3

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-0565
CVE-2019-0567
CVE-2019-0541
CVE-2019-0568
CVE-2019-0566
CVE-2019-0539
Оказываемое влияние
?
ACE 
[?]

PE 
[?]
Связанные продукты
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
CVE-2019-05417.5Critical
CVE-2019-05654.2Warning
CVE-2019-05674.2Warning
CVE-2019-05684.2Warning
CVE-2019-05664.3Warning
CVE-2019-05394.2Warning
KB list

4480978
4480962
4480966
4480116
4480961
4480973
4480963
4480968
4480970
4480975
4480965

Microsoft official advisories
Microsoft Security Update Guide