
====================================================================

                                  CERT-Renater

                       Note d'Information No. 2016/VULN100
_____________________________________________________________________

DATE                : 09/03/2016

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows version 10 running Microsoft Edge.

======================================================================
https://technet.microsoft.com/en-us/library/security/MS16-024
_____________________________________________________________________

MS16-024: Cumulative Security Update for Microsoft Edge (3142019)

Bulletin Number: MS16-024

Bulletin Title: Cumulative Security Update for Microsoft Edge

Severity: Critical

KB Article: 3142019

Version: 1.0

Published Date: March 8, 2016


Executive Summary

This security update resolves vulnerabilities in Microsoft Edge. The
most severe of the vulnerabilities could allow remote code execution if
a user views a specially crafted webpage using Microsoft Edge. An
attacker who successfully exploited the vulnerabilities could gain the
same user rights as the current user. Customers whose accounts are
configured to have fewer user rights on the system could be less
impacted than those who operate with administrative user rights.

This security update is rated Critical for Microsoft Edge on Windows 10.


Affected Software

Microsoft Edge

   Windows 10 for 32-bit Systems[1] (3140745)

   Windows 10 for x64-based Systems[1] (3140745)

   Windows 10 Version 1511 for 32-bit Systems[1] (3140768)

   Windows 10 Version 1511 for x64-based Systems[1] (3140768)

[1]Windows 10 updates are cumulative. In addition to containing
non-security updates, they also contain all of the security fixes for
all of the Windows 10-affected vulnerabilities shipping with the
monthly security release. The updates are available via the Microsoft
Update Catalog.


Vulnerability Information


Multiple Microsoft Edge Memory Corruption Vulnerabilities

Multiple remote code execution vulnerabilities exist when Microsoft
Edge improperly accesses objects in memory. The vulnerabilities could
corrupt memory in such a way that an attacker could execute arbitrary
code in the context of the current user.

An attacker could host a specially crafted website that is designed to
exploit the vulnerabilities through Microsoft Edge, and then convince a
user to view the website. The attacker could also take advantage of
compromised websites and websites that accept or host user-provided
content or advertisements by adding specially crafted content that
could exploit the vulnerability. In all cases, however, an attacker
would have no way to force users to view the attacker-controlled
content. Instead, an attacker would have to convince users
to take action, typically by way of enticement in an email or Instant
Messenger message, or by getting them to open an attachment sent
through email.

An attacker who successfully exploited the vulnerabilities could gain
the same user rights as the current user. If the current user is logged
on with administrative user rights, an attacker who successfully
exploited the vulnerabilities could take control of an affected system.
An attacker could then install programs; view, change, or delete data;
or create new accounts with full user rights. The update addresses the
vulnerability by modifying how Microsoft Edge handles objects in memory.

The following table contains links to the standard entry for each
vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title    CVE number    Publicly disclosed   Exploited

Microsoft Browser Memory
Corruption Vulnerability 	CVE-2016-0102	No 	  No

Microsoft Browser Memory
Corruption Vulnerability 	CVE-2016-0105	No 	  No

Microsoft Browser Memory
Corruption Vulnerability 	CVE-2016-0109	No 	  No

Microsoft Browser Memory
Corruption Vulnerability 	CVE-2016-0110	No 	  No

Microsoft Browser Memory
Corruption Vulnerability 	CVE-2016-0111	No 	  No

Microsoft Edge Memory
Corruption Vulnerability 	CVE-2016-0116	No 	  No

Microsoft Edge Memory
Corruption Vulnerability 	CVE-2016-0123	No 	  No

Microsoft Edge Memory
Corruption Vulnerability 	CVE-2016-0124	No 	  No

Microsoft Edge Memory
Corruption Vulnerability 	CVE-2016-0129	No 	  No

Microsoft Edge Memory
Corruption Vulnerability 	CVE-2016-0130	No 	  No


Microsoft Edge Information
Disclosure Vulnerability - CVE-2016-0125

An information disclosure vulnerability exists when Microsoft Edge
improperly handles the referrer policy. An attacker who successfully
exploited the vulnerability could gain information about the request
context or browsing history of a user.

To exploit the vulnerability, an attacker must convince a user who is
accessing a secure website to click a link that takes the user to a
malicious website. The update addresses the vulnerability by changing
how Microsoft Edge handles the referrer policy.

The following table contains links to the standard entry for each
vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title    CVE number   Publicly disclosed   Exploited

Microsoft Edge Information
Disclosure Vulnerability    CVE-2016-0125   No 	          No

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================





