SB2019010805 - Multiple vulnerabilities in Microsoft Edge 



SB2019010805 - Multiple vulnerabilities in Microsoft Edge

Published: January 8, 2019 Updated: January 14, 2019

Security Bulletin ID SB2019010805
Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 80% Low 20%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Memory corruption (CVE-ID: CVE-2019-0539)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when the Chakra scripting engine handles objects in memory in Microsoft Edge. A remote attacker can create a specially crafted website, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Privilege escalation (CVE-ID: CVE-2019-0566)

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The vulnerability exists due to an error in Microsoft Edge Browser Broker COM object. A remote attacker can trick the victim into visiting a specially crafted website and use the Browser Broker COM object to gain elevated privileges.


3) Memory corruption (CVE-ID: CVE-2019-0568)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when the Chakra scripting engine handles objects in memory in Microsoft Edge. A remote attacker can create a specially crafted website, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


4) Memory corruption (CVE-ID: CVE-2019-0567)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when the Chakra scripting engine handles objects in memory in Microsoft Edge. A remote attacker can create a specially crafted website, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


5) Memory corruption (CVE-ID: CVE-2019-0565)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when Microsoft Edge improperly accesses objects in memory. A remote attacker can create a specially crafted website, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.