Palo Alto Networks Unit 42 Vulnerability Research November 2017 Disclosures
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11791 | ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11834. NVD description · AI analysis pending | 3.1 | 5% |
| — | ||
| CVE-2017-11855 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11856. NVD description · AI analysis pending | 7.5 group max | 49% | PoC |
| — |
Full article213 words · extracted from unit42.paloaltonetworks.com · click to collapse
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered four vulnerabilities addressed by the Microsoft Security Response Center as part of their November 2017 security update release.
| CVE | Vulnerability Name | Affected Products | Maximum Severity Rating | Impact | Researcher(s) |
| CVE-2017-11855 | Internet Explorer Memory Corruption Vulnerability | Internet Explorer 9, 10, 11 | Critical | Remote Code Execution (RCE) | Hui Gao |
| CVE-2017-11856 | Internet Explorer Memory Corruption Vulnerability | Internet Explorer 11 | Critical | Remote Code Execution (RCE) | Hui Gao and Zhanglin He |
| CVE-2017-11791 | Scripting Engine Information Disclosure Vulnerability | Internet Explorer 9, 10, 11; Microsoft Edge | Important | Information Disclosure | Hui Gao |
| CVE-2017-11834 | Scripting Engine Information Disclosure Vulnerability | Internet Explorer 9, 10, 11 | Important | Information Disclosure | Hui Gao |
For current customers with a Threat Prevention subscription, Palo Alto Networks has also released IPS signatures providing proactive protection from these vulnerabilities. Traps, Palo Alto Networks advanced endpoint solution, can block memory corruption based exploits of this nature.
Palo Alto Networks is a regular contributor to vulnerability research in Microsoft, Adobe, Apple, Google Android and other ecosystems. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing the information with the security community, we are removing weapons used by attackers to threaten users, and compromise enterprise, government, and service provider networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/unit42-palo-alto-networks-unit-42-vulnerability-research-november-2017-disclosures/