Operating System:

[Win]

Published:

20 December 2018

Protect yourself against future threats.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2018.0310
                December 2018 update for Internet Explorer
                             20 December 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Internet Explorer
Operating System:     Windows
Impact/Access:        Execute Arbitrary Code/Commands -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2018-8653  
Member content until: Saturday, January 19 2019

Comment: There are reports of this vulnerability being actively exploited.

OVERVIEW

        Microsoft has released an out of band security patch update for the 
        month of December 2018. 
        
        This update resolves 1 vulnerabilities across the following 
        products: [1]
        
         Internet Explorer 10
         Internet Explorer 11
         Internet Explorer 9


IMPACT

        Microsoft has given the following details regarding these 
        vulnerabilities. [1]
        
         Details         Impact                   Severity
         CVE-2018-8653   Remote Code Execution    Critical


MITIGATION

        Microsoft recommends updating the software with the version made 
        available on the Microsoft Update Catalogue for the following 
        Knowledge Base articles. [1]
        
        KB4483187, KB4483230, KB4483234, KB4483235, KB4483232, KB4483228, 
        KB4483229, KB4483187


REFERENCES

        [1] CVE-2018-8653 | Scripting Engine Memory Corruption Vulnerability
            https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8653

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXBrdlGaOgq3Tt24GAQjaVhAAhbSzUi8JGCtkJseOO+yHItpETvXmXMnD
WqHNqiwNMX3L5LiHqjH0kindvAD54XjMFqF/lBGeWRhbPjyMgBw+SunWpCXvCzhI
jObdodFYTIOjrnJlGDGxJWeZXBY+3VUowHtFNAzextyAQM9tA+dcv1COkisV176t
Hjra9lWbUn9nSsz3Am0UxtHd/xndk40pxEXoXZDuW+Ay7Acs01iR682jULvhPmC6
B6XPTKkuSyEHCzF/s+okyHT2+iHkKpum5bAWDURnNstAoHyDjER56ekRC5/P0y7B
UwazJZPqWqJmxPnuRdKdYY8FZtz+ilOGDleK0oMWC/pn2iA4BtVCz9aNSFHaWFW7
aa0+f4b5fR2ecEwOyPZfkbHojLTUNPFCtXyOxkXYucpU+lt4NHDdXtPF6026N2mD
Lva09yNAEdMiqaomdLB3BHjPVfY1awfmgDIBLMfeIou4Qobtu9jyS8yJ0aiNS2Rn
q1Vu+Ie9W+QgwrwSrf3H4rIacmGKaxFcucxAK5XHOrAtoVqMPBY5UQDyL6DAnfpV
hSh9cRegon5QeOr8pxHcZGpRlxxPg29ZCvwB4nQwh+FALLtExtmmX2TBsNskH9TA
DDAhZx1xd66iVW7r6RPup5bRaVs8sgx7dzx/403MV0yZ3h6UzbqtiUAi7bOtxUyw
r7qI3TxJPgY=
=NFav
-----END PGP SIGNATURE-----