Rewterz Threat Advisory – Apache PDFBox Denial of Service vulnerability
October 8, 2018Rewterz Threat Advisory – Oracle Linux update for kernel-uek
October 12, 2018Rewterz Threat Advisory – Apache PDFBox Denial of Service vulnerability
October 8, 2018Rewterz Threat Advisory – Oracle Linux update for kernel-uek
October 12, 2018Microsoft Internet Explorer 11 was found vulnerable to multiple threats that may cause memory corruption.
IMPACT: CRITICAL
PUBLISH DATE: 12-10-2018
OVERVIEW
Two errors were found in the Microsoft Internet Explorer 11. The errors occur when handling objects in memory and can be exploited to corrupt memory and subsequently execute arbitrary code.
ANALYSIS
When Internet Explorer improperly accesses objects in memory, it gives rise to some errors leading to remote code execution vulnerabilities. The vulnerabilities corrupt the memory in such a way that attackers may execute arbitrary codes on the system using user privileges of the current logged-in user.
The vulnerabilities get more harmful if the current user happens to be logged on with administrative user rights. It’ll let an attacker take control of a system and enable them to modify or delete data, install malicious programs or create more accounts with administrative rights.
In case of an exploit, the attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer. They will then proliferate the link of that website most likely through phishing emails to convince users to visit it.
Compromised websites can also be used for the attack. To exploit the vulnerability, attackers can also submit specially crafted files on websites that accept ads or user-generated content.
Apart from the memory corruption damage, a failed attack will cause denial of service conditions. The security update involves a modification of Internet Explorer in how it handles objects in memory.
AFFECTED PRODUCTS
Microsoft Internet Explorer 11.x
UPDATES
Apply following updates.
- Internet Explorer 11 on Windows 10 Version 1709 for 32-bit Systems (KB4462918):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462918
- Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems (KB4462919):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462919
- Internet Explorer 11 on Windows 10 for 32-bit Systems (KB4462922):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462922
- Internet Explorer 11 on Windows Server 2016 (KB4462917):
- Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems (KB4462917):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462917
- Internet Explorer 11 on Windows 10 Version 1703 for 32-bit Systems (KB4462937):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462937
- Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems (KB4464330):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
- Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems (KB4464330):
- Internet Explorer 11 on Windows Server 2019 (KB4464330):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
- Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems (KB4464330):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
- Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems (KB4462917):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462917
- Internet Explorer 11 on Windows 10 Version 1709 for x64-based Systems (KB4462918):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462918
- Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems (KB4462919):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462919
- Internet Explorer 11 on Windows 10 for x64-based Systems (KB4462922):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462922
- Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 (KB4462923):
- Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4462923):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462923
- Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 (KB4462923):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462923
- Internet Explorer 11 on Windows RT 8.1 (KB4462926):
Apply update (please see the vendor’s service database for details).
- Internet Explorer 11 on Windows 8.1 for x64-based systems (KB4462926):
- Internet Explorer 11 on Windows Server 2012 R2 (KB4462926):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462926
- Internet Explorer 11 on Windows 8.1 for 32-bit systems (KB4462926):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462926
- Internet Explorer 11 on Windows 10 Version 1703 for x64-based Systems (KB4462937):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462937
- Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 (KB4462949):
- Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4462949):
- Internet Explorer 11 on Windows 8.1 for x64-based systems (KB4462949):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
- Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 (KB4462949):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
- Internet Explorer 11 on Windows Server 2012 R2 (KB4462949):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
- Internet Explorer 11 on Windows 8.1 for 32-bit systems (KB4462949):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
If you think you’re a victim of a cyber-attack, immediately send an email to info@rewterz.com.