Zero-day vulnerability in Microsoft Internet Explorer

Memory corruption
CVE-2018-8653

Vulnerability details

Advisory: SB2018122001 - Memory Corruption in Microsoft Internet Explorer

Vulnerable component: Microsoft Internet Explorer

CVE-ID: CVE-2018-8653

CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Description:

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing web pages. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note: this vulnerability is being actively exploited in the wild.

Latest references in media:

- Microsoft Patches Internet Explorer Zero-Day Reported by Google [2019-02-12 22:20:13]

- Microsoft issues emergency fix for Internet Explorer zero-day [2019-01-30 22:13:10]

- Patch Tuesday, January 2019 Edition [2019-01-10 17:50:15]

- Patch Tuesday, January 2019 Edition [2019-01-09 16:11:16]

- JANUARY 2019 – Microsoft Patch Tuesday [2019-01-09 13:10:19]

- Microsoft Kicks Off 2019 With Medium Patch Load [2019-01-09 11:00:04]

- Microsoft has released January 2019 Patch Tuesday security updates to patch a total 49 vulnerabilities in its Windows operating systems and other products. [2019-01-09 08:40:06]

- Remote Code Execution Bugs Are Primary Focus of January Patch Tuesday [2019-01-08 23:40:07]

- Microsoft Issues Multiple Critical Patches for Edge Browser [2019-01-08 21:50:09]

- Be of good cheer: The Windows/Office December patching minefield looks clear [2018-12-25 01:40:09]

- Links 20/12/2018: Skrooge 2.17.0, Linux Mint 19.1, HardenedBSD 12 [2018-12-21 11:31:46]

- Microsoft Issues Emergency Patch for IE Flaw [2018-12-21 11:30:07]

- Attackers Use Scripting Flaw in Internet Explorer, Forcing Microsoft Patch [2018-12-20 23:10:06]

- Update now! Microsoft patches another zero-day flaw [2018-12-20 23:01:17]

- Update now! Microsoft patches another zero-day flaw [2018-12-20 23:00:16]

- Zero-day vulnerability in Microsoft Internet Explorer; update your system now [2018-12-20 22:21:17]

- Microsoft Issues Emergency Fix for IE Zero Day [2018-12-20 20:40:19]

- Microsoft IE Zero Day Gets Emergency Patch [2018-12-20 15:40:14]

- Microsoft issues emergency fix for Internet Explorer zero-day [2018-12-20 15:34:05]

- Microsoft patches Internet Explorer to stop PC takeover attacks - CNET [2018-12-20 14:50:08]

- Microsoft issues emergency patch for IE Zero Day exploited in the wild [2018-12-20 10:40:12]

- Microsoft Released Security Updates for Internet Explorer zero-day [2018-12-20 09:11:11]

- Microsoft releases an EMERGENCY security update to patch a remote code execution vulnerability (CVE-2018-8653) in Internet Explorer that is currently being exploited in the wild [2018-12-20 08:40:08]

- Google Finds Internet Explorer Zero-Day Exploited in Targeted Attacks [2018-12-20 07:10:12]

- Microsoft delivers emergency patch for under-attack IE [2018-12-20 02:40:07]

- Microsoft Issues Emergency Fix for IE Zero Day [2018-12-19 22:31:12]

- Microsoft releases security update for new IE zero-day | ZDNet [2018-12-19 22:20:08]

- On the first day of Christmas, Microsoft gave to me... an emergency out-of-band security patch for IE [2018-12-19 20:30:02]

- Microsoft Releases Out-of-Band Security Update for Internet Explorer RCE Zero-Day [2018-12-19 20:10:21]

- December 2018 Security Update Release [2018-12-19 19:31:12]

Vulnerability Scanning SaaS

Vulnerability scanning SaaS service is online 3-rd generation vulnerability scanner with scheduled assessments and vulnerability subscription. You can use service to check security of your network perimeter.