CERT-In Vulnerability Note
CIVN-2016-0310
Multiple Vulnerabilities in Microsoft Internet Explorer
Original Issue Date:December 14, 2016
Severity Rating: HIGH
Software Affected
- Microsoft Windows 7 for 32-bit Systems SP1
- Microsoft Windows 7 for 32-bit
- Microsoft Windows 7 for x64-based Systems SP1
- Microsoft Windows 7 for x64-based
- Microsoft Windows 7 Home Premium - Sp1 X64
- Microsoft Windows 7 Home Premium - Sp1 X32
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2008 for 32-bit Systems SP2
- Microsoft Windows Server 2008 for 32-bit
- Microsoft Windows Server 2008 for x64-based Systems SP2
- Microsoft Windows Server 2008 for x64-based
- Microsoft Windows Server 2008 R2 for x64-based Systems SP1
- Microsoft Windows Vista SP2
- Microsoft Windows Vista SP1
- Microsoft Windows Vista x64 Edition SP2
- Microsoft Windows Vista x64 Edition SP1
- Microsoft Windows Vista x64
- Microsoft Windows 10 for 32-bit
- Microsoft Windows 10 for x64-based
- Microsoft Windows 10 version 1511 for 32-bit
- Microsoft Windows 10 version 1511 for x64-based
- Microsoft Windows 8.1 for 32-bit
- Microsoft Windows 8.1 for x64-based
- Microsoft Windows Rt 8.1
- Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
- Microsoft Windows Server 2012 R2
- Microsoft Windows 8 for 32-bit
- Microsoft Windows 8 for x64-based
- Microsoft Windows RT 0
- Microsoft Windows Server 2012
- Microsoft Windows 10 Version 1607 for 32-bit
- Microsoft Windows 10 Version 1607 for x64-based
- Microsoft Windows Server 2016 for x64-based
Overview
Multiple vulnerabilities have been reported in Microsoft Internet Explorer which could be exploited by an attacker to execute arbitrary code, bypass security restrictions, gain elevated privileges and obtain sensitive information.
Description
1. Multiple Information Disclosure Vulnerabilities in Internet Explorer
(
CVE-2016-7278
CVE-2016-7282
CVE-2016-7284
)
These vulnerabilities exist due to improper handling of objects in memory by the Microsoft Browser. A remote attacker could exploit these vulnerabilities by convincing a user to visit a specially crafted website to disclose sensitive information in memory.
2. Multiple Browser memory corruption vulnerabilities
(
CVE-2016-7279
CVE-2016-7283
)
These vulnerabilities exist when Microsoft Browsers improperly accesses objects in memory. A remote attacker could exploit these vulnerabilities by convincing a user to visit a specially crafted website using Internet Explorer. Successful exploitation of these vulnerabilities could trigger memory corruption which could allow the attacker to execute arbitrary code with the privileges of the target user.
3. Security Feature Bypass Vulnerability
(
CVE-2016-7281
)
A security feature bypass vulnerability exists due to improper implementation of the same origin policy for scripts running inside the Web Workers. A remote attacker could exploit this vulnerability by convincing a user to visit a specially crafted website. Successful exploitation of this vulnerability allows the attacker to bypass security restrictions, which could be leveraged to conduct further attacks.
4. Multiple Scripting Engine Memory Corruption Vulnerabilities
(
CVE-2016-7202
CVE-2016-7287
)
These vulnerabilities exists due to improper handling of objects in memory. A remote attacker could exploit these vulnerabilities by enticing a user to visit a specially crafted website or open a malicious file using Internet Explorer which could lead to memory corruption. Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code with the privileges of the target user.
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS16-144
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/MS16-144
References
Microsoft
https://technet.microsoft.com/library/security/MS16-144
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=49452
https://tools.cisco.com/security/center/viewAlert.x?alertId=49951
https://tools.cisco.com/security/center/viewAlert.x?alertId=49952
https://tools.cisco.com/security/center/viewAlert.x?alertId=49953
https://tools.cisco.com/security/center/viewAlert.x?alertId=49954
https://tools.cisco.com/security/center/viewAlert.x?alertId=49955
https://tools.cisco.com/security/center/viewAlert.x?alertId=49956
https://tools.cisco.com/security/center/viewAlert.x?alertId=49957
CVE Name
CVE-2016-7202
CVE-2016-7278
CVE-2016-7279
CVE-2016-7281
CVE-2016-7282
CVE-2016-7283
CVE-2016-7284
CVE-2016-7287
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|