‫ Microsoft Internet Explorer Multiple Vulnerabilities

ID: IRCAD2015053922
Release Date: 2015-05-12
Criticality level: Highly critical
Software:
Microsoft Internet Explorer 10.x
Microsoft Internet Explorer 11.x
Microsoft Internet Explorer 6.x
Microsoft Internet Explorer 7.x
Microsoft Internet Explorer 8.x
Microsoft Internet Explorer 9.x
Description:
Multiple vulnerabilities have been reported in Microsoft Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a user's system.
1) An unspecified error can be exploited to bypass ASLR.
2) An error when handling scripts can be exploited to run a script with otherwise restricted elevated privileges.
3) Another error when handling scripts can be exploited to run a script with otherwise restricted elevated privileges.
4) Another error when handling scripts can be exploited to run a script with otherwise restricted elevated privileges.
5) Another error when handling scripts can be exploited to run a script with otherwise restricted elevated privileges.
6) An error related to the Windows clipboard can be exploited do disclose Windows clipboard contents.
7) An unspecified error can be exploited to corrupt memory.
8) Another unspecified error can be exploited to corrupt memory.
9) Another unspecified error can be exploited to corrupt memory.
10) Another unspecified error can be exploited to corrupt memory.
11) Another unspecified error can be exploited to corrupt memory.
12) A type confusion error related to CSecurityContext objects can be exploited to corrupt memory.
13) Another unspecified error can be exploited to corrupt memory.
14) A use-after-free error when handling Tree::TableGridBlock objects can be exploited to corrupt memory.
15) Another unspecified error can be exploited to corrupt memory.
16) Another unspecified error can be exploited to corrupt memory.
17) Another unspecified error can be exploited to corrupt memory.
18) A use-after-free error when handling CTitleElement objects can be exploited to corrupt memory.
19) Another use-after-free error when handling CTitleElement objects can be exploited to corrupt memory.
20) Another unspecified error can be exploited to corrupt memory.
Successful exploitation of the vulnerabilities #7 through #‫20 allows execution of arbitrary code.
Solution
Apply update.
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10
Internet Explorer 11
References:
MS15-043 (KB3049563):
ZDI:
Secunia:
 

نظرات

بدون نظر
شما برای نظر دادن باید وارد شوید

نوشته

 
تاریخ ایجاد: 9 خرداد 1394

امتیاز

امتیاز شما
تعداد امتیازها:0