Lucene search

K
kasperskyKaspersky LabKLA11058
HistoryApr 11, 2017 - 12:00 a.m.

KLA11058 Multiple vulnerabilities in Microsoft Edge and Internet Explorer

2017-04-1100:00:00
Kaspersky Lab
threats.kaspersky.com
34

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.881 High

EPSS

Percentile

98.7%

Multiple serious vulnerabilities have been found in Microsoft Internet Explorer and Microsoft Edge. Malicious users can exploit these vulnerabilities to to gain privileges, execute arbitrary code, bypass security restrictions and obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. An improper handling of objects in memory in Microsoft browsers can be exploited remotely via a specially designed website to execute arbitrary code;
  2. An incorrect access to objects in memory in Microsoft Edge can be exploited remotely via a specially designed website to execute arbitrary code;
  3. An improper handling of objects in memory in the JScript and VBScript engines in Internet Explorer can be exploited remotely via a specially crafted website to execute arbitrary code;
  4. An incorrect access to objects in memory in Internet Explorer can be exploited remotely via a specially designed website to execute arbitrary code;
  5. An improper validation of documents in Microsoft Edge Content Security Policy can be exploited remotely via certain specially designed documents to trick a user into loading a web page with malicious content;
  6. An incorrect handling of objects in memory in the Chakra scripting engine can be exploited remotely via a specially designed website to obtain sensitive information;
  7. An improper enforcing of cross-domain policies in Internet Explorer can be exploited remotely via a specially designed website to gain privileges.

Original advisories

CVE-2017-0205

CVE-2017-0203

CVE-2017-0202

CVE-2017-0201

CVE-2017-0200

CVE-2017-0093

CVE-2017-0208

CVE-2017-0210

CVE-2017-0093

CVE-2017-0200

CVE-2017-0201

CVE-2017-0202

CVE-2017-0203

CVE-2017-0205

CVE-2017-0208

CVE-2017-0210

Exploitation

Public exploits exist for this vulnerability.

Related products

Microsoft-Internet-Explorer

Microsoft-Edge

CVE list

CVE-2017-0093 critical

CVE-2017-0200 critical

CVE-2017-0201 critical

CVE-2017-0202 critical

CVE-2017-0203 warning

CVE-2017-0205 critical

CVE-2017-0208 warning

CVE-2017-0210 warning

KB list

4015549

4015550

4015221

4014661

4015551

4015219

4015217

4015583

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Microsoft EdgeMicrosoft Internet Explorer versions 9 through 11

References

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.881 High

EPSS

Percentile

98.7%