CERT-In Vulnerability Note
CIVN-2016-0311
Multiple Vulnerabilities in Microsoft Edge
Original Issue Date:December 14, 2016
Severity Rating: HIGH
Software Affected
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016 for x64-based Systems
Overview
Multiple vulnerabilities have been reported in Microsoft Edge and Internet Explorer that could allow a remote attacker to bypass security restrictions, conduct arbitrary code execution and obtain potentially sensitive information on the targeted system.
Description
1. Memory Corruption Vulnerabilities
(
CVE-2016-7181
CVE-2016-7279
)
These vulnerabilities exist in Microsoft Edge due to improper handling of memory operations while handling crafted content. An attacker could exploit these vulnerabilities by influencing a user to follow a malicious link or open a malicious file. Successful exploitation could allow a remote attacker to execute arbitrary code on the targeted system.
2. Information Disclosure Vulnerabilities
(
CVE-2016-7206
CVE-2016-7280
CVE-2016-7282
)
These vulnerabilities exist in Microsoft Edge due to improper validation of user-supplied input under specific conditions. An attacker could exploit these vulnerabilities by influencing a targeted user to view a malicious website. Successful exploitation could allow a remote attacker to conduct arbitrary code execution that could also leads to information disclosure on the targeted system.
3. Multiple Scripting Engine Memory Corruption Vulnerabilities
(
CVE-2016-7287
CVE-2016-7286
CVE-2016-7288
CVE-2016-7296
CVE-2016-7297
)
These vulnerabilities exist in Microsoft Edge and Internet Explorer due to improper handling of memory operations by the Microsoft scripting engines while handling crafted content. An attacker could exploit these vulnerabilities by influencing a user to follow a malicious link or open a malicious file. Successful exploitation could allow a remote attacker to execute arbitrary code on the targeted system.
4. Security Feature Bypass Vulnerability
(
CVE-2016-7281
)
This vulnerability exists in Microsoft Edge and Internet Explorer due to improper implementation of the same origin policy for scripts running inside the Web Workers. An attacker could exploit this vulnerability by influencing a targeted user to open a web page with malicious content. Successful exploitation could allow a remote attacker to bypass security restrictions, that leads to conduct further attacks.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS16-145
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms16-145
References
Security Tracker
http://securitytracker.com/id/1037444
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=49959
https://tools.cisco.com/security/center/viewAlert.x?alertId=49960
https://tools.cisco.com/security/center/viewAlert.x?alertId=49952
https://tools.cisco.com/security/center/viewAlert.x?alertId=49961
https://tools.cisco.com/security/center/viewAlert.x?alertId=49953
https://tools.cisco.com/security/center/viewAlert.x?alertId=49954
https://tools.cisco.com/security/center/viewAlert.x?alertId=49962
https://tools.cisco.com/security/center/viewAlert.x?alertId=49957
https://tools.cisco.com/security/center/viewAlert.x?alertId=49963
https://tools.cisco.com/security/center/viewAlert.x?alertId=49964
https://tools.cisco.com/security/center/viewAlert.x?alertId=49965
CVE Name
CVE-2016-7181
CVE-2016-7206
CVE-2016-7279
CVE-2016-7280
CVE-2016-7281
CVE-2016-7282
CVE-2016-7286
CVE-2016-7287
CVE-2016-7288
CVE-2016-7296
CVE-2016-7297
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|