SB2017111417 - Multiple vulnerabilities in Microsoft Edge
Published: November 14, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 24 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: CVE-2017-11791)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft browsers by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
2) Information disclosure (CVE-ID: CVE-2017-11803)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to improper handling of objects in memory by Microsoft Edge. A remote attacker can create a specially crafted Web site, trick the victim into visiting it and read arbitrary data.
Successful exploitation of this vulnerability results in information disclosure.
3) Memory corruption (CVE-ID: CVE-2017-11827)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the way Microsoft browsers access objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
4) Memory corruption (CVE-ID: CVE-2017-11871)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
5) Memory corruption (CVE-ID: CVE-2017-11858)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the way Microsoft browsers access objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
6) Memory corruption (CVE-ID: CVE-2017-11866)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
7) Memory corruption (CVE-ID: CVE-2017-11846)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
8) Memory corruption (CVE-ID: CVE-2017-11843)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
9) Memory corruption (CVE-ID: CVE-2017-11840)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
10) Memory corruption (CVE-ID: CVE-2017-11838)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
11) Memory corruption (CVE-ID: CVE-2017-11833)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the way Microsoft Edge handles cross-origin requests. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
12) Memory corruption (CVE-ID: CVE-2017-11836)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
13) Memory corruption (CVE-ID: CVE-2017-11873)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
14) Memory corruption (CVE-ID: CVE-2017-11870)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
15) Memory corruption (CVE-ID: CVE-2017-11862)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
16) Memory corruption (CVE-ID: CVE-2017-11861)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
17) Memory corruption (CVE-ID: CVE-2017-11845)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to Microsoft Edge improperly accesses objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
18) Information disclosure (CVE-ID: CVE-2017-11844)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to improper handling of objects in memory by Microsoft Edge. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and read arbitrary files.
19) Memory corruption (CVE-ID: CVE-2017-11841)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
20) Memory corruption (CVE-ID: CVE-2017-11839)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
21) Memory corruption (CVE-ID: CVE-2017-11837)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in remote code execution.
22) Security restrictions bypass (CVE-ID: CVE-2017-11874)
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.
The vulnerability exists due to how memory is accessed in code compiled by the Edge Just-In-Time (JIT) compiler. A remote attacker can browse to a malicious website, bypass Control Flow Guard (CFG) and perform further attacks.
23) Open redirect (CVE-ID: CVE-2017-11872)
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper handling of redirect requests by Microsoft Edge. A remote attacker can bypass Cross-Origin Resource Sharing (CORS) redirect restrictions, trick the victim into visiting a specially crafted website and force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice.
24) Security restrictions bypass (CVE-ID: CVE-2017-11863)
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists in Microsoft Edge due to improper validation of the malicious input by the Edge Content Security Policy (CSP). A remote attacker can bypass security restrictions and trick the victim into loading a page containing malicious content.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11791
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11803
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11827
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11871
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11858
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11866
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11846
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11843
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11840
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11838
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11833
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11836
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11873
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11870
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11862
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11861
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11845
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11844
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11841
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11839
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11837
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11874
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11872
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11863