CERT-In Vulnerability Note
CIVN-2014-0279
Remote Code Execution Vulnerability in the VBScript Scripting Engine in Microsoft Internet Explorer
Original Issue Date:December 10, 2014
Severity Rating: HIGH
Systems Affected
- Windows Vista and Vista x64 Edition SP2
- Windows Server 2003 and x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Server 2008 for 32-bit Systems and x64-based Systems SP2
- Windows Server 2008 for Itanium-based Systems SP2
- Windows 7 for 32-bit and x64-based Systems SP1
- Windows Server 2008 R2 for x64-based Systems SP1
- Windows Server 2008 R2 for Itanium-based Systems SP1
Component Affected
- VBScript 5.6 (Internet Explorer 6)
- VBScript 5.7 (Internet Explorer 7)
- VBScript 5.8 (Internet Explorer 8)
Overview
A remote code execution vulnerability has been reported in the VBScript scripting engine in Microsoft Internet Explorer, which could be exploited by the remote attackers to execute arbitrary code or gain elevated privileges in the context of currently logged-in user on a targeted system.
Description
This vulnerability exist in the VBScript scripting engine in Microsoft Internet Explorer due to improper accessing of objects in the memory. A remote attacker could exploit this vulnerability by enticing the targeted user to visit a website specially designed to invoke the IE rendering engine which could result in memory corruption.
Successful exploitation of this vulnerability could lead to execution of an arbitrary code & compromise the system in the context of the currently logged-in user on a targeted system.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS14-084
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-084.aspx
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36583
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=71504&om_rssid=sr-advisories
CVE Name
CVE-2014-6363
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|