Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Microsoft Internet Explorer 11 was found vulnerable to multiple threats that may cause memory corruption.
IMPACT: CRITICAL
PUBLISH DATE: 12-10-2018
OVERVIEW
Two errors were found in the Microsoft Internet Explorer 11. The errors occur when handling objects in memory and can be exploited to corrupt memory and subsequently execute arbitrary code.
ANALYSIS
When Internet Explorer improperly accesses objects in memory, it gives rise to some errors leading to remote code execution vulnerabilities. The vulnerabilities corrupt the memory in such a way that attackers may execute arbitrary codes on the system using user privileges of the current logged-in user.
The vulnerabilities get more harmful if the current user happens to be logged on with administrative user rights. It’ll let an attacker take control of a system and enable them to modify or delete data, install malicious programs or create more accounts with administrative rights.
In case of an exploit, the attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer. They will then proliferate the link of that website most likely through phishing emails to convince users to visit it.
Compromised websites can also be used for the attack. To exploit the vulnerability, attackers can also submit specially crafted files on websites that accept ads or user-generated content.
Apart from the memory corruption damage, a failed attack will cause denial of service conditions. The security update involves a modification of Internet Explorer in how it handles objects in memory.
AFFECTED PRODUCTS
Microsoft Internet Explorer 11.x
UPDATES
Apply following updates.
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462918
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462919
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462922
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462917
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462937
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4464330
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462917
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462918
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462919
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462922
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462923
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462923
Apply update (please see the vendor’s service database for details).
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462926
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462926
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462937
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4462949
If you think you’re a victim of a cyber-attack, immediately send an email to info@rewterz.com.