Lucene search

K
kasperskyKaspersky LabKLA11265
HistoryJun 12, 2018 - 12:00 a.m.

KLA11265 Multiple vulnerabilities in Microsoft Internet Explorer & Edge

2018-06-1200:00:00
Kaspersky Lab
threats.kaspersky.com
55

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.951 High

EPSS

Percentile

99.3%

Multiple vulnerabilities were found in Microsoft Browsers. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Chakra Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  2. A memory corruption vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to execute arbitrary code.
  3. A security feature bypass vulnerability in Internet Explorer can be exploited remotely via specially crafted to bypass security restrictions.
  4. An information disclosure vulnerability in Microsoft Edge based on Edge HTML can be exploited remotely via specially crafted content to obtain sensitive information.
  5. A memory corruption vulnerability in Internet Explorer can be exploited remotely via specially crafted website to execute arbitrary code.
  6. A security feature bypass vulnerability in Microsoft Edge can be exploited remotely via specially crafted website to bypass security restrictions.
  7. A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
  8. An information disclosure vulnerability in Microsoft Edge can be exploited remotely to obtain sensitive information.
  9. A memory corruption vulnerability in ChakraCore can be exploited remotely to execute arbitrary code.

Technical details

Vulnerability (4) allows to bypass Mark of the Web Tagging (MOTW).

Original advisories

CVE-2018-8227

CVE-2018-8229

CVE-2018-8236

CVE-2018-8113

CVE-2018-8234

CVE-2018-8249

CVE-2018-8110

CVE-2018-8235

CVE-2018-8267

CVE-2018-0871

CVE-2018-8111

CVE-2018-0978

CVE-2018-8243

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Microsoft-Internet-Explorer

Microsoft-Edge

ChakraCore

CVE list

CVE-2018-8227 critical

CVE-2018-8229 critical

CVE-2018-8243 critical

CVE-2018-8236 critical

CVE-2018-8113 warning

CVE-2018-8234 warning

CVE-2018-8249 critical

CVE-2018-8110 critical

CVE-2018-8235 warning

CVE-2018-8267 critical

CVE-2018-0871 warning

CVE-2018-8111 critical

CVE-2018-0978 critical

KB list

4284860

4284874

4284826

4284835

4284880

4284819

4230450

4284855

4284815

4532693

4532691

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Internet Explorer 10Internet Explorer 11Internet Explorer 9ChakraCoreMicrosoft Edge (EdgeHTML-based)

References

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.951 High

EPSS

Percentile

99.3%