

Rewterz Threat Advisory – CVE-2018-0732 – IBM Lotus Protector for Mail Security OpenSSL Denial of Service Vulnerability
December 13, 2018
Rewterz Threat Advisory – CVE-2018-8604 – Microsoft Exchange Server 2016 Profile Data Manipulation Vulnerability
December 13, 2018
Rewterz Threat Advisory – CVE-2018-0732 – IBM Lotus Protector for Mail Security OpenSSL Denial of Service Vulnerability
December 13, 2018
Rewterz Threat Advisory – CVE-2018-8604 – Microsoft Exchange Server 2016 Profile Data Manipulation Vulnerability
December 13, 2018Multiple vulnerabilities have been reported in Microsoft Edge, which can be exploited by malicious people to compromise a vulnerable system.
IMPACT: CRITICAL
PUBLISH DATE: 13-DEC-2018
OVERVIEW
An arbitrary code subsequently executes when handling objects in memory. This can be exploited to corrupt memory. This error is related to chakra scripting engine. Updates are available.
ANALYSIS
Five remote code execution vulnerabilities have been discovered in Microsoft Edge. Identified as CVE-2018-8624, CVE-2018-8618, CVE-2018-8617, CVE-2018-8629 and CVE-2018-8583, each one of these vulnerabilities are unique from the others.
The flaw exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka “Chakra Scripting Engine Memory Corruption Vulnerability.”
This affects Microsoft Edge, ChakraCore.
AFFECTED PRODUCTS
Microsoft Edge
UPDATES
Apply relevant updates as given below.
- Microsoft Edge on Windows 10 Version 1703 for x64-based Systems (KB4471327):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471327
- Microsoft Edge on Windows 10 Version 1703 for 32-bit Systems (KB4471327):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471327
- Microsoft Edge on Windows 10 Version 1809 for ARM64-based Systems (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Microsoft Edge on Windows 10 Version 1809 for x64-based Systems (KB4471332):
- Microsoft Edge on Windows Server 2019 (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Microsoft Edge on Windows 10 Version 1809 for 32-bit Systems (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Microsoft Edge on Windows 10 Version 1709 for 32-bit Systems (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
- Microsoft Edge on Windows 10 Version 1803 for 32-bit Systems (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Microsoft Edge on Windows 10 Version 1709 for x64-based Systems (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
- Microsoft Edge on Windows 10 Version 1803 for x64-based Systems (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Microsoft Edge on Windows 10 Version 1803 for ARM64-based Systems (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Microsoft Edge on Windows 10 Version 1709 for ARM64-based Systems (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
- Microsoft Edge on Windows Server 2016 (KB4471321):
- Microsoft Edge on Windows 10 Version 1607 for x64-based Systems (KB4471321):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321
- Microsoft Edge on Windows 10 Version 1607 for 32-bit Systems (KB4471321):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321
- Microsoft Edge on Windows 10 for x64-based Systems (KB4471323):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323
- Microsoft Edge on Windows 10 for 32-bit Systems (KB4471323):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323
Note: Security updates for Windows 10 and Windows Server 2016 are available via e.g. Windows Update or Windows Update Catalog only.
If you think you’re the victim of a cyber-attack, immediately send an email to soc@rewterz.com for a quick response