Google publishes remote code vulnerability in Microsoft browsers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0037 | Type Confusion RCE in Microsoft Internet Explorer and Edge CVE-2017-0037 is a type confusion flaw (CWE-843) in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, located in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function of mshtml.dll. It is triggered when the browser processes a crafted Cascading Style Sheets token sequence combined with JavaScript that operates on a TH (table header) element, typically delivered via a malicious or compromised web page. An attacker who successfully exploits it can execute arbitrary code in the context of the browser process. Any user running the affected legacy Microsoft browsers is exposed, which historically meant most Windows desktops. The flaw was publicly disclosed via Google Project Zero after a 90-day deadline passed, public proof-of-concept exploits are available, and it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), confirming in-the-wild exploitation. Do: Apply Microsoft security updates per vendor instructions (the flaw was addressed in Microsoft's March 2017 Patch Tuesday, which followed the Project Zero disclosure), prioritizing systems in CISA KEV scope. Inventory for any hosts still running IE 10/11 or legacy (pre-Chromium) Edge and retire or isolate them, as legacy Microsoft browsers are end-of-life. As an interim mitigation, avoid using affected browsers for untrusted web content, since exploitation requires rendering attacker-crafted CSS/JavaScript. | 8.1 | 80% | KEV PoC ×5 |
| massHundreds of millions of Windows endpoints (IE 11 and legacy Edge were bundled with Windows 7/8.1/10) | |
| CVE-2017-0038 | gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220. NVD description · AI analysis pending | 5.5 | 82% |
| — |
Full article699 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The flaw could affect all users running vulnerable software — which includes anyone using the bundled browser in Windows 7, Windows 8.1, and Windows 10.
Google’s Project Zero published an unpatched and very severe vulnerability in the Microsoft Edge and Internet Explorer version 11 browsers Monday, after a 90-day deadline expired without a fix from Microsoft’s engineers. The publication, which means hackers will be able to write exploits for the affected software, appears to be the latest result of Microsoft’s shocking and still mysterious decision to cancel its monthly software update for February.
According to DHS’s National Vulnerability Database, the bug is a so-called “type confusion flaw” and could allow an attacker to remotely execute arbitrary code when the browser visits a specially crafted malicious website. Remote code execution, or RCE, bugs are among the most severe kind of software vulnerabilities, because they allow hackers to take over a system running the affected software.
The flaw could affect all users running vulnerable software — which includes anyone using the bundled browser in Windows 7, Windows 8.1, and Windows 10.
The vulnerability is classed as “high severity” and coded CVE-2017-0037.
Google’s vulnerability researchers — organized in the company’s Project Zero bug hunting team — have a very strict disclosure deadline. At the end of the 90-day period, the vulnerability will be published — whether or not it’s been fixed.
“Deadlines appear to be working to improve patch times and end user security — especially when enforced consistently,” Google engineers wrote in a 2015 blog post discussing their disclosure practices.
“I really didn’t expect this one to miss the deadline,” wrote Project Zero researcher Ivan Fratric, who disclosed the vulnerability privately to Microsoft on Nov. 25 in a technical report. He wrote a proof-of-concept exploit for the flaw, which is included in the disclosure, but is remaining silent for the time being.
“I will not make any further comments on exploitability, at least not until the bug is fixed. The report has too much info on that as it is,” he wrote.
But Microsoft engineers — who have patched security flaws and provided updates for their software on the second Tuesday of the month for almost a decade and a half — suddenly canceled February’s “Patch Tuesday” distribution in a painfully brief blog entry the day it was due.
“This month, we discovered a last minute issue that could impact some customers and was not resolved in time for our planned updates today,” wrote the Microsoft Security Research Center Team Feb. 14.
“After considering all options, we made the decision to delay this month’s updates.” The following day they announced that February patches would be issued on March 14.
But that means that they are missing the 90-day deadline for other vulnerabilities they were alerted to last year, as well. One of those vulnerabilities (CVE-2017-0038), of medium severity, also reported by Project Zero, was privately disclosed to Microsoft on Nov. 16 and published 90 days later.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-google-project-zero-vulnerability-cve-2017-0037/