CERT-In Vulnerability Note
CIVN-2015-0275
Multiple Vulnerabilities in Microsoft Edge Browser
Original Issue Date:November 12, 2015
Severity Rating: HIGH
Software Affected
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Microsoft Edge
Overview
Multiple vulnerabilities have been reported in Microsoft Edge Browser which could be exploited by remote attacker to bypass security restrictions and execute arbitrary code on the target system.
Description
1. Multiple Memory Corruption Vulnerabilities
(
CVE-2015-6064
CVE-2015-6073
CVE-2015-6078
)
Multiple memory corruption vulnerabilities exist in Microsoft edge due to improper handling of objects in the memory by the affected software. A remote attacker could exploit these vulnerabilities by convincing a user to visit a specially crafted website or to open a malicious file. Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code with the privileges of the user.
2. ASLR Security Bypass Vulnerability
(
CVE-2015-6088
)
ASLR Security Bypass Vulnerability exist in Microsoft edge due to non-usage of the Address Space Layout Randomization (ASLR) security feature which could allow an attacker to more reliably predict memory offsets of instructions in call stacks. An attacker could exploit this vulnerability by convincing a user to visit a specially crafted website to bypass ASLR security feature. Successful exploitation of this vulnerability in conjunction with other vulnerabilities could allow a remote attacker to execute arbitrary code on the target system.
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS15-113
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-113.aspx
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-113.aspx
SecurityTracker
http://securitytracker.com/id/1034113
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=41823
http://tools.cisco.com/security/center/viewAlert.x?alertId=41831
http://tools.cisco.com/security/center/viewAlert.x?alertId=41836
http://tools.cisco.com/security/center/viewAlert.x?alertId=41845
CVE Name
CVE-2015-6064
CVE-2015-6073
CVE-2015-6078
CVE-2015-6088
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|