فا

‫ Microsoft Internet Explorer Multiple Vulnerabilities

ID: IRCAD2014123678
Release Date: 2014-12-09
Criticality level: Highly critical
Software:
Microsoft Internet Explorer 10.x
Microsoft Internet Explorer 11.x
Microsoft Internet Explorer 6.x
Microsoft Internet Explorer 7.x
Microsoft Internet Explorer 8.x
Microsoft Internet Explorer 9.x
Description:
Multiple vulnerabilities have been reported in Microsoft Internet Explorer, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
1) A use-after-free error when handling the CSetTimeoutInfo object can be exploited to corrupt memory.
2) An unspecified error can be exploited to bypass XSS filter.
3) A use-after-free error when handling the CTreePos object can be exploited to corrupt memory.
4) Another unspecified error can be exploited to corrupt memory.
5) An unspecified error can be exploited to bypass XSS filter.
6) An unspecified error can be exploited to corrupt memory.
7) An unspecified error can be exploited to bypass ASLR.
8) An unspecified error can be exploited to corrupt memory.
9) Another unspecified error can be exploited to corrupt memory.
10) An error within the "RtfToForeign32" function can be exploited to cause a buffer overflow.
11) A use-after-free error when handling HTML elements created via the "execCommand" method can be exploited to corrupt memory.
12) An error within the "LineBoxBuilder::FindWord()" function can be exploited to cause a buffer overflow.
13) A type confusion error within the processing of the event handler of CInputElement elements can be exploited to corrupt memory.
Successful exploitation of vulnerabilities #1, #3, #4, #6, and #8 through #‫13 allows execution of arbitrary code.
Solution
Apply updates.
Internet Explorer 6
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Internet Explorer 7
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Internet Explorer 8
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Internet Explorer 9
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Internet Explorer 10
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows 8 for 32-bit Systems
Windows 8 for x64-based Systems
Windows Server 2012
Internet Explorer 11
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows 8.1  for 32-bit Systems
Windows 8.1  for x64-based Systems
Windows Server 2012 R2
References:
Microsoft (KB3008923):
ZDI:
Secunia:
 

نظرات

بدون نظر
شما برای نظر دادن باید وارد شوید

نوشته

 
تاریخ ایجاد: 21 آذر 1393

امتیاز

امتیاز شما
تعداد امتیازها:0