KLA11501
Multiple vulnerabilities in Microsoft Developer Tools
Обновлено: 22/07/2020
Дата обнаружения
11/06/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A spoofing vulnerability in Azure DevOps Server can be exploited remotely to spoof user interface.
Пораженные продукты

ChakraCore
Azure DevOps Server 2019
Microsoft Edge (EdgeHTML-based)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-1003
CVE-2019-0996
Оказываемое влияние
?
ACE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Edge
ChakraCore
Microsoft Azure
CVE-IDS
CVE-2019-10030.0Unknown
CVE-2019-09960.0Unknown
Microsoft official advisories
Microsoft Security Update Guide