Vulnerabilities > CVE-2016-3198 - 7PK - Security Features vulnerability in Microsoft Edge
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS16-068 |
bulletin_url | |
date | 2016-06-14T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 3163656 |
knowledgebase_url | |
severity | Critical |
title | Cumulative Security Update for Microsoft Edge |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS16-068.NASL |
description | The version of Microsoft Edge installed on the remote Windows host is missing Cumulative Security Update 3163656. It is, therefore, affected by multiple vulnerabilities : - A security feature bypass vulnerability exists due to a failure to properly validate specially crafted documents. An unauthenticated, remote attacker can exploit this vulnerability by convincing a user to load a page or visit a website containing malicious content, allowing the attacker to bypass the Edge Content Security Policy (CSP). (CVE-2016-3198) - Multiple remote code execution vulnerabilities exist in the Chakra JavaScript engine due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit these vulnerabilities by convincing a user to visit a specially crafted website or open a specially crafted Microsoft Office document that hosts the Edge rendering engine, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-3199, CVE-2016-3202, CVE-2016-3214, CVE-2016-3222) - Multiple information disclosure vulnerabilities exist due to improper parsing of .pdf files. An unauthenticated, remote attacker can exploit these vulnerabilities by convincing a user to open a specially crafted .pdf file, resulting in the disclosure of sensitive information in the context of the current user. (CVE-2016-3201, CVE-2016-3215) - A remote code execution vulnerability exists due to improper parsing of .pdf files. An unauthenticated, remote attacker can exploit this vulnerability by convincing a user to open a specially crafted .pdf file, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-3203) Note that CVE-2016-3214, CVE-2016-3215, and CVE-2016-3222 only affect Windows 10 version 1511. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 91597 |
published | 2016-06-14 |
reporter | This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/91597 |
title | MS16-068: Cumulative Security Update for Microsoft Edge (3163656) |
code |
|