CERT-In Vulnerability Note
CIVN-2015-0253
Multiple Vulnerabilities in Microsoft Edge
Original Issue Date:October 14, 2015
Severity Rating: MEDIUM
Software Affected
- Microsoft Edge for Windows 10 (32-bit and x64-based Systems)
Overview
Multiple vulnerabilities have been reported in Microsoft Edge which could be exploited by remote attackers to obtain potentially sensitive information or bypass security restrictions on the affected system.
Description
1. Information Disclosure Vulnerability
(
CVE-2015-6057
)
An Information disclosure vulnerability exists in Microsoft Edge due to the inadequacy to properly handle memory objects by certain functions. A remote attacker could exploit this vulnerability by convincing the user to view a specially crafted website to obtain memory contents from the affected Windows system. The attacker could use the obtained information to further compromise the affected system.
2. XSS Filter Bypass Vulnerability
(
CVE-2015-6058
)
A cross-site scripting (XSS) filter bypass vulnerability exists in Microsoft Edge due to the improper handling of HTML attribute in HTTP response data. A remote attacker could exploit this vulnerability by enticing the user to view a specially crafted website which is designed to invoke malformed scripts to run in the wrong security context, leading to information disclosure or could conduct further attacks.
Solution
Apply appropriate updates as mentioned in
MS15-107
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/MS15-107
References
Microsoft
https://technet.microsoft.com/library/security/MS15-107
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=76980
http://www.symantec.com/security_response/vulnerability.jsp?bid=76990
Security Tracker
http://www.securitytracker.com/id/1033802
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=41358
http://tools.cisco.com/security/center/viewAlert.x?alertId=41359
CVE Name
CVE-2015-6057
CVE-2015-6058
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|