KLA11575
Multiple vulnerabilities in Microsoft Developer Tools
Обновлено: 11/10/2019
Дата обнаружения
08/10/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Azure App Service can be exploited remotely to execute arbitrary code.
  2. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted content to execute arbitrary code.
  4. An information disclosure vulnerability in Open Enclave SDK can be exploited remotely to obtain sensitive information.
  5. An information disclosure vulnerability in SQL Server Management Studio can be exploited remotely to obtain sensitive information.
Пораженные продукты

Azure App Service on Azure Stack
ChakraCore
Microsoft Edge (EdgeHTML-based)
Open Enclave SDK
SQL Server Management Studio 18.3.1
SQL Server Management Studio 18.3

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-1372
CVE-2019-1366
CVE-2019-1308
CVE-2019-1369
CVE-2019-1376
CVE-2019-1313
CVE-2019-1307
CVE-2019-1335
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]
Связанные продукты
ChakraCore
CVE-IDS
CVE-2019-13720.0Unknown
CVE-2019-13660.0Unknown
CVE-2019-13080.0Unknown
CVE-2019-13690.0Unknown
CVE-2019-13760.0Unknown
CVE-2019-13130.0Unknown
CVE-2019-13070.0Unknown
CVE-2019-13350.0Unknown
KB list

4520010
4520008
4519998
4517389
4519338
4520011
4520004

Microsoft official advisories
Microsoft Security Update Guide