• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – Adobe Reader / Acrobat Multiple Vulnerabilities
December 14, 2018
Rewterz Threat Advisory – Microsoft .NET Framework Multiple Vulnerabilities
December 17, 2018

Rewterz Threat Advisory – Microsoft Internet Explorer Multiple Vulnerabilities

December 14, 2018

SEVERITY: High

 

 

CATEGORY: Vulnerability

 

 

PUBLISH DATE: December 14, 2018

 

 

ANALYSIS SUMMARY:

 

 

The following vulnerabilities have been discovered in Microsoft Internet Explorer which can cause memory corruption, bypassing of certain security restrictions and execution of arbitrary code, if exploited.

 

CVE-2018-8643: Scripting engine improperly handles objects in memory in Internet Explorer, leading to execution of arbitrary code.

 

CVE-2018-8619: Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, leading to potential remote code execution.

 

CVE-2018-8625: VBScript engine improperly handles objects in memory, leading to remote code execution vulnerability.

 

CVE-2018-8631: Internet Explorers handles objects in memory improperly, leading to remote code execution vulnerability.

 

IMPACT

 

Remote code execution, Security bypass, Memory corruption

 

 

AFFECTED VENDORS

 

Microsoft

 

 

AFFECTED PRODUCTS

 

Microsoft Internet Explorer 9.x

Microsoft Internet Explorer 10.x

Microsoft Internet Explorer 11.x

 

 

REMEDIATION

 

Apply update.

 

Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 (KB4470199):

Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4470199):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 (KB4470199): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 11 on Windows 8.1 for x64-based systems (KB4470199):

Internet Explorer 11 on Windows Server 2012 R2 (KB4470199):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 11 on Windows 8.1 for 32-bit systems (KB4470199): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 10 on Windows Server 2012 (KB4470199): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 (KB4471318):

Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4471318):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471318

 

 

Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 (KB4471318): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471318

 

 

Internet Explorer 11 on Windows RT 8.1 (KB4471320):

Apply update (please see the vendor’s service database for details).

 

 

Internet Explorer 11 on Windows 8.1 for x64-based systems (KB4471320):

Internet Explorer 11 on Windows Server 2012 R2 (KB4471320):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471320

 

 

Internet Explorer 11 on Windows 8.1 for 32-bit systems (KB4471320):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471320

 

 

Internet Explorer 11 on Windows Server 2016 (KB4471321):

Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems (KB4471321):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321

 

 

Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems (KB4471321):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321

 

 

Internet Explorer 11 on Windows 10 for x64-based Systems (KB4471323):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323

 

 

Internet Explorer 11 on Windows 10 for 32-bit Systems (KB4471323):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323

 

 

Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2 (KB4471325):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471325

 

 

Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4471325):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471325

 

 

Internet Explorer 11 on Windows 10 Version 1703 for x64-based Systems (KB4471327):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471327

 

 

Internet Explorer 11 on Windows 10 Version 1703 for 32-bit Systems (KB4471327):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471327

 

Internet Explorer 10 on Windows Server 2012 (KB4471330):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471330

 

 

Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems (KB4471332):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332

 

 

Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems (KB4471332):

Internet Explorer 11 on Windows Server 2019 (KB4471332):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332

 

 

Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems (KB4471332):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332

 

 

Internet Explorer 11 on Windows 10 Version 1709 for 32-bit Systems (KB4471329):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329

 

 

Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems (KB4471324):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324

 

 

Internet Explorer 11 on Windows 10 Version 1709 for x64-based Systems (KB4471329):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329

 

 

Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems (KB4471324):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324

 

 

Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2 (KB4470199):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4470199):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4470199

 

 

Internet Explorer 11 on Windows 10 Version 1803 for ARM64-based Systems (KB4471324):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324

 

 

Internet Explorer 11 on Windows 10 Version 1709 for ARM64-based Systems (KB4471329):

https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329

 

Note: Security updates for Windows RT 8.1, Windows Server 2016, and Windows 10 are available via e.g. Windows Update or Windows Update Catalog only.

  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.