Microsoft Browser Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction. An attacker who successfully exploited this vulnerability could allow an attacker to obtain browser frame or window state from a different domain. For an attack to be successful, an attacker must persuade a user to open a malicious website from a secure website. This update addresses the vulnerability by denying permission to read the state of the object model, to which frames or windows on different domains should not have access.
🎯 Affected products23
- Internet Explorer 10 on Windows Server 2012
- Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1703 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1703 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1709 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1709 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems
- Internet Explorer 11 on Windows 10 for 32-bit Systems
- Internet Explorer 11 on Windows 10 for x64-based Systems
- Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
- Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
- Internet Explorer 11 on Windows 8.1 for 32-bit systems
- Internet Explorer 11 on Windows 8.1 for x64-based systems
- Internet Explorer 11 on Windows RT 8.1
- Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Internet Explorer 11 on Windows Server 2012 R2
- Internet Explorer 11 on Windows Server 2016
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems
- Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems
✅ Remediation
KB4343909 (Security Update) KB4343892 (Security Update) KB4343901 (Monthly Rollup) KB4343205 (IE Cumulative) KB4343885 (Security Update) KB4343897 (Security Update) KB4343887 (Security Update) KB4343900 (Monthly Rollup) KB4343898 (Monthly Rollup)
🔗 References (10)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8351
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343909
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343892
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343901
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343205
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343885
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343897
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343887
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343900
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343898