Microsoft Internet Explorer Scripting Engine CVE-2018-0955 Remote Memory Corruption Vulnerability
Bugtraq ID:
103993
Class:
Design Error
CVE:
CVE-2018-0955
Remote:
Yes
Local:
No
Published:
May 08 2018 12:00AM
Updated:
May 08 2018 12:00AM
Credit:
Yuki Chen of Qihoo 360 Vulcan Team
Vulnerable:
Microsoft Internet Explorer 9
+
Microsoft Windows 7
+
Microsoft Windows 7
+
Microsoft Windows 7
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for 32-bit Systems 0
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 for x64-based Systems 0
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X64
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows 7 Home Premium - Sp1 X32
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 R2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems SP2
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for 32-bit Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems SP2
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 for x64-based Systems 0
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP2
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista SP1
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP2
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition SP1
+
Microsoft Windows Vista x64 Edition 0
+
Microsoft Windows Vista x64 Edition 0
+
Microsoft Windows Vista x64 Edition 0
Microsoft Internet Explorer 11
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for 32-bit Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for 32-bit Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 version 1511 for x64-based Systems 0
+
Microsoft Windows 10 Version 1607 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1607 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1607 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1607 for x64-based Systems 0
+
Microsoft Windows 10 Version 1607 for x64-based Systems 0
+
Microsoft Windows 10 Version 1607 for x64-based Systems 0
+
Microsoft Windows 10 version 1703 for 32-bit Systems 0
+
Microsoft Windows 10 version 1703 for 32-bit Systems 0
+
Microsoft Windows 10 version 1703 for 32-bit Systems 0
+
Microsoft Windows 10 version 1703 for x64-based Systems 0
+
Microsoft Windows 10 version 1703 for x64-based Systems 0
+
Microsoft Windows 10 version 1703 for x64-based Systems 0
+
Microsoft Windows 10 version 1709 for 32-bit Systems 0
+
Microsoft Windows 10 version 1709 for 32-bit Systems 0
+
Microsoft Windows 10 version 1709 for x64-based Systems 0
+
Microsoft Windows 10 version 1709 for x64-based Systems 0
+
Microsoft Windows 10 Version 1803 for 32-bit Systems 0
+
Microsoft Windows 10 Version 1803 for x64-based Systems 0
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for 32-bit Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows 8.1 for x64-based Systems 0
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Rt 8.1 -
+
Microsoft Windows Server 2016
+
Microsoft Windows Server 2016
+
Microsoft Windows Server 2016
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP2
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
+
Microsoft Windows Server 2012 R2 0
Microsoft Internet Explorer 10
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for 32-bit Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 7 for x64-based Systems SP1
+
Microsoft Windows 8 for 32-bit Systems 0
+
Microsoft Windows 8 for 32-bit Systems 0
+
Microsoft Windows 8 for x64-based Systems 0
+
Microsoft Windows 8 for x64-based Systems 0
+
Microsoft Windows RT 0
+
Microsoft Windows RT 0
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
+
Microsoft Windows Server 2012 0
+
Microsoft Windows Server 2012 0
+
Microsoft Windows Server 2012 0
Not Vulnerable:
Discussion
Microsoft Internet Explorer Scripting Engine CVE-2018-0955 Remote Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial of service conditions.
Solution / Fix
Microsoft Internet Explorer Scripting Engine CVE-2018-0955 Remote Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Internet Explorer Scripting Engine CVE-2018-0955 Remote Memory Corruption Vulnerability