Google Does It Again: Discloses Unpatched Microsoft Edge and IE Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0037 | Type Confusion RCE in Microsoft Internet Explorer and Edge CVE-2017-0037 is a type confusion flaw (CWE-843) in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, located in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function of mshtml.dll. It is triggered when the browser processes a crafted Cascading Style Sheets token sequence combined with JavaScript that operates on a TH (table header) element, typically delivered via a malicious or compromised web page. An attacker who successfully exploits it can execute arbitrary code in the context of the browser process. Any user running the affected legacy Microsoft browsers is exposed, which historically meant most Windows desktops. The flaw was publicly disclosed via Google Project Zero after a 90-day deadline passed, public proof-of-concept exploits are available, and it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), confirming in-the-wild exploitation. Do: Apply Microsoft security updates per vendor instructions (the flaw was addressed in Microsoft's March 2017 Patch Tuesday, which followed the Project Zero disclosure), prioritizing systems in CISA KEV scope. Inventory for any hosts still running IE 10/11 or legacy (pre-Chromium) Edge and retire or isolate them, as legacy Microsoft browsers are end-of-life. As an interim mitigation, avoid using affected browsers for untrusted web content, since exploitation requires rendering attacker-crafted CSS/JavaScript. | 8.1 | 80% | KEV PoC ×5 |
| massHundreds of millions of Windows endpoints (IE 11 and legacy Edge were bundled with Windows 7/8.1/10) |
Full article506 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalFeb 25, 2017
This month has yet been kind of interesting for cyber security researchers, with Google successfully cracked SHA1 and the discovery of Cloudbleed bug in Cloudflare that caused the leakage of sensitive information across sites hosted behind Cloudflare.
Besides this, Google last week disclosed an unpatched vulnerability in Windows Graphics Device Interface (GDI) library, which affects Microsoft's Windows operating systems ranging from Windows Vista Service Pack 2 to the latest Windows 10.
While the Windows vulnerability has yet to be patched by the company, Google today released the details of another unpatched Windows security flaw in its browser, as Microsoft did not act within its 90-day disclosure deadline.
The vulnerability (CVE-2017-0037), discovered and disclosed by Google Project Zero team's researcher Ivan Fratric, is a so-called "type confusion flaw" in a module in Microsoft Edge and Internet Explorer that potentially leads to arbitrary code execution.
Proof-of-Concept Code Released!
This time, with the details of this arbitrary code execution bug, the researcher has also published a proof-of-concept exploit that can crash Edge and IE, opening the door for potential hackers to execute code and gain administrator privileges on the affected systems.
Fratric says he successfully ran his PoC code on the 64-bit version of IE on Windows Server 2012 R2, but both 32-bit IE 11, as well as Microsoft Edge, is affected by the same vulnerability.
In short, the vulnerability affects all Windows 7, Windows 8.1, and Windows 10 users.
You can know more details about the recently disclosed flaw on Google's bug report blog, along with proof-of-concept code that causes a crash of the browsers, though sophisticated hackers can build more dangerous exploits as well.
This vulnerability was reported to Microsoft on November 25, and it went public on February 25, after Google Project Zero's 90-day disclosure policy.
Three Unpatched, but Already Disclosed Windows Flaws
While Microsoft has delayed this month's Patch Tuesday and already has to patch two already disclosed, but unpatched vulnerabilities, it is hard to say if the company actually included a patch for this vulnerability discovered by Google in its next roll out of patches.
Yes, Microsoft has to patch two other severe security flaws as well, which have already been publicly disclosed with working exploit code but remain still unpatched, giving hackers enough time to target Windows users.
First one is a Windows SMB flaw that affects Windows 8, Windows 10 and Windows Server. The PoC exploit code of this flaw was released almost two weeks ago.
The other one is the vulnerability disclosed by Google last week that affects Microsoft's Windows operating systems ranging from Windows Vista Service Pack 2 to the latest Windows 10.
Meanwhile, just to remain on the safer side, Windows users are advised to replace their Internet Explorer and Edge browsers with a different one if possible and avoid clicking on suspicious links and websites they do not trust.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2017/02/google-microsoft-edge-bug.html