Security Updates for Internet Explorer (July 2018)

High Nessus Plugin ID 110991

Synopsis

The Internet Explorer installation on the remote host is affected by multiple vulnerabilities.

Description

The Internet Explorer installation on the remote host is
missing security updates. It is, therefore, affected by
multiple vulnerabilities :

- A remote code execution vulnerability exists in the way
the scripting engine handles objects in memory in
Microsoft browsers. The vulnerability could corrupt
memory in such a way that an attacker could execute
arbitrary code in the context of the current user. An
attacker who successfully exploited the vulnerability
could gain the same user rights as the current user.
(CVE-2018-8287, CVE-2018-8288, CVE-2018-8291)

- A security feature bypass vulnerability exists when
Microsoft Internet Explorer improperly handles requests
involving UNC resources. An attacker who successfully
exploited the vulnerability could force the browser to
load data that would otherwise be restricted.
(CVE-2018-0949)

- A remote code execution vulnerability exists in the way
that the scripting engine handles objects in memory in
Internet Explorer. The vulnerability could corrupt
memory in such a way that an attacker could execute
arbitrary code in the context of the current user. An
attacker who successfully exploited the vulnerability
could gain the same user rights as the current user.
(CVE-2018-8242, CVE-2018-8296)

Solution

Microsoft has released the following security updates to address this issue:
-KB4339093
-KB4338815
-KB4338830
-KB4338818

See Also

http://www.nessus.org/u?156c87ff

http://www.nessus.org/u?e0106ae8

http://www.nessus.org/u?0c32edc0

http://www.nessus.org/u?d021f588

Plugin Details

Severity: High

ID: 110991

File Name: smb_nt_ms18_jul_internet_explorer.nasl

Version: 1.4

Type: local

Agent: windows

Published: 2018/07/10

Modified: 2018/09/17

Dependencies: 93962, 57033, 13855

Risk Information

Risk Factor: High

CVSS Score Source: manual

CVSS Score Rationale: Using score from microsoft api, rce requires user interaction to exlpoit

CVSS v2.0

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Patch Publication Date: 2018/07/10

Vulnerability Publication Date: 2018/07/10

Reference Information

CVE: CVE-2018-0949, CVE-2018-8242, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296

BID: 104620, 104622, 104634, 104636, 104637, 104638

MSKB: 4339093, 4338815, 4338830, 4338818

MSFT: MS18-4339093, MS18-4338815, MS18-4338830, MS18-4338818