CERT-In Vulnerability Note
CIVN-2017-0184
Multiple Vulnerabilities in Microsoft Edge
Original Issue Date:December 14, 2017
Severity Rating: HIGH
Software Affected
- Windows 10 for 32-bit & x64-based Systems
- Windows 10 Version 1511 for 32-bit & x64-based Systems
- Windows 10 Version 1607 for 32-bit & x64-based Systems
- Windows 10 Version 1703 for 32-bit & x64-based Systems
- Windows 10 Version 1709 for 32-bit &x64-based Systems
- Windows Server 2016
Overview
Multiple vulnerabilities have been reported in Microsoft Edge which could be exploited by a remote attacker to execute arbitrary code and gain elevated privileges on the targeted system or obtain sensitive information.
Description
1. Microsoft Edge Memory Corruption Vulnerability
(
CVE-2017-11888
)
A remote code execution vulnerability exists in Microsoft Edge due to improper handling of objects in memory. A remote attacker could exploit this vulnerability by enticing a user to access specially crafted page containing malicious content or visiting a malicious website. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code with the privileges of the currently logged-in user. If the user has elevated privileges, the attacker could compromise the system completely.
2. Microsoft Scripting Engine Memory Corruption Vulnerabilities
(
CVE-2017-11889
CVE-2017-11893
CVE-2017-11894
CVE-2017-11895
CVE-2017-11905
CVE-2017-11908
CVE-2017-11909
CVE-2017-11910
CVE-2017-11911
CVE-2017-11912
CVE-2017-11914
CVE-2017-11918
)
Multiple remote code execution vulnerabilities exist in Microsoft Edge due to improper handling of objects in memory by scripting engine. A remote attacker could exploit these vulnerabilities by enticing a user to access specially crafted page containing malicious content or visiting a malicious website. Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code with the privileges of the currently logged-in user. If the user has elevated privileges, the attacker could compromise the system completely.
3. Microsoft Edge Information Disclosure Vulnerability
(
CVE-2017-11919
)
An information disclosure vulnerability exists in Microsoft Edge due to improper handling of memory objects in browsers by scripting engine. A remote attacker could exploit this vulnerability by persuading a user to visit specially crafted page containing malicious content or visiting a malicious website. A successful exploitation of this vulnerability could allow the remote attacker to access sensitive information on the targeted system, which could be used to conduct additional attacks.
Solution
Apply appropriate patch as mentioned in Microsoft Security Guidance
https://portal.msrc.microsoft.com/en-us/security-guidance
Vendor Information
Microsoft
https://portal.msrc.microsoft.com/en-us/security-guidance
References
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11888
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11889
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11893
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11894
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11895
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11905
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11908
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11909
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11910
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11911
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11912
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11914
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11918
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11919
Security Tracker
https://securitytracker.com/id/1039990
CISCO
https://tools.cisco.com/security/center/viewAlert.x?alertId=56133
https://tools.cisco.com/security/center/viewAlert.x?alertId=56134
https://tools.cisco.com/security/center/viewAlert.x?alertId=56136
https://tools.cisco.com/security/center/viewAlert.x?alertId=56138
https://tools.cisco.com/security/center/viewAlert.x?alertId=56143
https://tools.cisco.com/security/center/viewAlert.x?alertId=56146
https://tools.cisco.com/security/center/viewAlert.x?alertId=56147
https://tools.cisco.com/security/center/viewAlert.x?alertId=56148
https://tools.cisco.com/security/center/viewAlert.x?alertId=56149
https://tools.cisco.com/security/center/viewAlert.x?alertId=56150
https://tools.cisco.com/security/center/viewAlert.x?alertId=56152
https://tools.cisco.com/security/center/viewAlert.x?alertId=56154
https://tools.cisco.com/security/center/viewAlert.x?alertId=56155
CVE Name
CVE-2017-11911
CVE-2017-11888
CVE-2017-11889
CVE-2017-11893
CVE-2017-11894
CVE-2017-11895
CVE-2017-11905
CVE-2017-11908
CVE-2017-11909
CVE-2017-11910
CVE-2017-11912
CVE-2017-11914
CVE-2017-11918
CVE-2017-11919
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|