KLA11478
Multiple vulnerabilities in Microsoft Browsers
Обновлено: 16/07/2019
Дата обнаружения
14/05/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, bypass security restrictions, gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Microsoft browsers can be exploited remotely via specially crafted website to execute arbitrary code.
  2. Multiple memory corruption vulnerabilities in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A spoofing vulnerability in Internet Explorer can be exploited remotely via specially crafted website to spoof user interface.
  4. A security feature bypass vulnerability in Internet Explorer can be exploited remotely via specially crafted file to bypass security restrictions.
  5. Multiple memory corruption vulnerabilities in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  6. An elevation of privilege vulnerability in Microsoft Edge can be exploited remotely to gain privileges.
  7. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  8. Multiple memory corruption vulnerabilities in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  9. An information disclosure vulnerability in Internet Explorer can be exploited remotely via specially crafted content to obtain sensitive information.
Пораженные продукты

Internet Explorer 11
Internet Explorer 10
Internet Explorer 9
Microsoft Edge

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-0940
CVE-2019-0937
CVE-2019-0924
CVE-2019-0913
CVE-2019-0921
CVE-2019-0995
CVE-2019-0918
CVE-2019-0923
CVE-2019-0912
CVE-2019-0929
CVE-2019-0925
CVE-2019-0915
CVE-2019-0927
CVE-2019-0933
CVE-2019-0916
CVE-2019-0938
CVE-2019-0926
CVE-2019-0914
CVE-2019-0911
CVE-2019-0884
CVE-2019-0930
CVE-2019-0917
CVE-2019-0922
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Internet Explorer
Microsoft Edge
CVE-IDS
CVE-2019-09407.5Critical
CVE-2019-09374.2Warning
CVE-2019-09244.2Warning
CVE-2019-09134.2Warning
CVE-2019-09214.3Warning
CVE-2019-09957.3High
CVE-2019-09187.5Critical
CVE-2019-09234.2Warning
CVE-2019-09124.2Warning
CVE-2019-09297.5Critical
CVE-2019-09254.2Warning
CVE-2019-09154.2Warning
CVE-2019-09274.2Warning
CVE-2019-09334.2Warning
CVE-2019-09164.2Warning
CVE-2019-09384.2Warning
CVE-2019-09264.2Warning
CVE-2019-09144.2Warning
CVE-2019-09117.5Critical
CVE-2019-08847.5Critical
CVE-2019-09304.3Warning
CVE-2019-09174.2Warning
CVE-2019-09224.2Warning
KB list

4499179
4499181
4499164
4499171
4499167
4494441
4497936
4499151
4494440
4499154
4498206
4499149

Microsoft official advisories
Microsoft Security Update Guide