Lucene search

K
kasperskyKaspersky LabKLA10552
HistoryApr 14, 2015 - 12:00 a.m.

KLA10552 Code execution vulnerabilities in Internet Explorer

2015-04-1400:00:00
Kaspersky Lab
threats.kaspersky.com
37

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.834 High

EPSS

Percentile

98.5%

Multiple unspecified vulnerabilities were found in Microsoft Internet Explorer. By exploiting these vulnerabilities malicious users can execute arbitrary code or cause denial of service. These vulnerabilities can be exploited remotely via a specially designed web site.

Original advisories

MS15-032

CVE-2015-1667

CVE-2015-1661

CVE-2015-1662

CVE-2015-1668

CVE-2015-1666

CVE-2015-1657

CVE-2015-1659

CVE-2015-1660

CVE-2015-1652

CVE-2014-6374

CVE-2015-1665

Related products

Microsoft-Internet-Explorer

CVE list

CVE-2015-1667 critical

CVE-2015-1661 warning

CVE-2015-1662 critical

CVE-2015-1668 critical

CVE-2015-1666 critical

CVE-2015-1657 critical

CVE-2015-1659 critical

CVE-2015-1660 critical

CVE-2015-1652 critical

CVE-2014-6374 critical

CVE-2015-1665 critical

KB list

3038314

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Internet Explorer versions from 6 through 11

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.834 High

EPSS

Percentile

98.5%