Microsoft Internet Explorer Scripting Engine CVE-2018-0989 Information Disclosure Vulnerability
Bugtraq ID:
103624
Class:
Design Error
CVE:
CVE-2018-0989
Remote:
Yes
Local:
No
Published:
Apr 10 2018 12:00AM
Updated:
Apr 10 2018 12:00AM
Credit:
Yuki Chen of Qihoo 360 Vulcan Team
Vulnerable:
Microsoft Internet Explorer 9
+
Microsoft Windows 7
+
Microsoft Windows 7
+
Microsoft Windows 7
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition 0
+
Microsoft Windows Vista x64 Edition 0
+
Microsoft Windows Vista x64 Edition 0
Microsoft Internet Explorer 11
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 Version 1607 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1607 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1607 for x64-based Systems 0
+
Microsoft Windows 10 Version 1607 for x64-based Systems 0
+
Microsoft Windows 10 version 1703 for 32-bit Systems 0
+
Microsoft Windows 10 version 1703 for 32-bit Systems 0
+
Microsoft Windows 10 version 1703 for x64-based Systems 0
+
Microsoft Windows 10 version 1703 for x64-based Systems 0
+
Microsoft Windows 10 version 1709 for 32-bit Systems 0
+
Microsoft Windows 10 version 1709 for x64-based Systems 0
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Server 2016
+
Microsoft Windows Server 2016
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
Microsoft Internet Explorer 10
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 8 for 32-bit Systems 0
+
Microsoft Windows 8 for 32-bit Systems 0
+
Microsoft Windows 8 for x64-based Systems 0
+
Microsoft Windows 8 for x64-based Systems 0
+
Microsoft Windows RT 0
+
Microsoft Windows RT 0
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2012 0
+
Microsoft Windows Server 2012 0
+
Microsoft Windows Server 2012 0
Not Vulnerable:
Discussion
Microsoft Internet Explorer Scripting Engine CVE-2018-0989 Information Disclosure Vulnerability
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Internet Explorer 9, 10 and 11 are vulnerable.
Solution / Fix
Microsoft Internet Explorer Scripting Engine CVE-2018-0989 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Internet Explorer Scripting Engine CVE-2018-0989 Information Disclosure Vulnerability