SB2017111417 - Multiple vulnerabilities in Microsoft Edge



SB2017111417 - Multiple vulnerabilities in Microsoft Edge

Published: November 14, 2017

Security Bulletin ID SB2017111417
Severity
High
Patch available
YES
Number of vulnerabilities 24
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 79% Low 21%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 24 secuirty vulnerabilities.


1) Memory corruption (CVE-ID: CVE-2017-11791)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft browsers by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


2) Information disclosure (CVE-ID: CVE-2017-11803)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to improper handling of objects in memory by Microsoft Edge. A remote attacker can create a specially crafted Web site, trick the victim into visiting it and read arbitrary data.

Successful exploitation of this vulnerability results in information disclosure.


3) Memory corruption (CVE-ID: CVE-2017-11827)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the way Microsoft browsers access objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


4) Memory corruption (CVE-ID: CVE-2017-11871)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.



5) Memory corruption (CVE-ID: CVE-2017-11858)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the way Microsoft browsers access objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.



6) Memory corruption (CVE-ID: CVE-2017-11866)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


7) Memory corruption (CVE-ID: CVE-2017-11846)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


8) Memory corruption (CVE-ID: CVE-2017-11843)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


9) Memory corruption (CVE-ID: CVE-2017-11840)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


10) Memory corruption (CVE-ID: CVE-2017-11838)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


11) Memory corruption (CVE-ID: CVE-2017-11833)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the way Microsoft Edge handles cross-origin requests. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


12) Memory corruption (CVE-ID: CVE-2017-11836)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


13) Memory corruption (CVE-ID: CVE-2017-11873)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


14) Memory corruption (CVE-ID: CVE-2017-11870)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


15) Memory corruption (CVE-ID: CVE-2017-11862)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


16) Memory corruption (CVE-ID: CVE-2017-11861)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


17) Memory corruption (CVE-ID: CVE-2017-11845)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to Microsoft Edge improperly accesses objects in memory. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


18) Information disclosure (CVE-ID: CVE-2017-11844)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to improper handling of objects in memory by Microsoft Edge. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and read arbitrary files.


19) Memory corruption (CVE-ID: CVE-2017-11841)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


20) Memory corruption (CVE-ID: CVE-2017-11839)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


21) Memory corruption (CVE-ID: CVE-2017-11837)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of objects in memory in Microsoft Edge by the scripting engine. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in remote code execution.


22) Security restrictions bypass (CVE-ID: CVE-2017-11874)

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.

The vulnerability exists due to how memory is accessed in code compiled by the Edge Just-In-Time (JIT) compiler. A remote attacker can browse to a malicious website, bypass Control Flow Guard (CFG) and perform further attacks.


23) Open redirect (CVE-ID: CVE-2017-11872)

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper handling of redirect requests by Microsoft Edge. A remote attacker can bypass Cross-Origin Resource Sharing (CORS) redirect restrictions, trick the victim into visiting a specially crafted website and force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice.


24) Security restrictions bypass (CVE-ID: CVE-2017-11863)

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists in Microsoft Edge due to improper validation of the malicious input by the Edge Content Security Policy (CSP). A remote attacker can bypass security restrictions and trick the victim into loading a page containing malicious content.


Remediation

Install update from vendor's website.

References