CVE-2018-8351

Description

An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka Microsoft Browser Information Disclosure Vulnerability. This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.

Risk Information

Base Score
4.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
15.346

Associated Vulnerability

VulnerabilityOS Platform
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4343887) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4343887) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4343887) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4343887) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4343887) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4343887) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4343892) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4343892) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4343898)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4343898)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4343898)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4343909) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4343909) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4343909) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4343909) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4343909) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4343909) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 (1709) for x64-based Systems (KB4343897) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4343897) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4343897) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4343897) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2016 (1709) for x64-based Systems (KB4343897) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4343897) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4343885) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4343885) - DeltaWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4343885) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4343885) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4343900)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4343900)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4343900)Windows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 10 for Windows Server 2012 (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows 8.1 (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows Server 2012 R2 (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 9 for Windows Server 2008 (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows 7 (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows 7 for x64-based Systems (KB4343205) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Internet Explorer 11 for Windows 8.1 for x64-based Systems (KB4343205) - CumulativeWindows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4343901)Windows
Microsoft COM for Windows Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4343897)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-250172018-08 Delta Update for Windows 10 Version 1607 for x64-based Systems (KB4343887)
PATCH-250182018-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4343887)
PATCH-250192018-08 Delta Update for Windows 10 Version 1607 for x86-based Systems (KB4343887)
PATCH-250202018-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4343887)
PATCH-250212018-08 Delta Update for Windows Server 2016 for x64-based Systems (KB4343887)
PATCH-250222018-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4343887)
PATCH-250232018-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4343892)
PATCH-250242018-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4343892)
PATCH-250652018-08 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4343898)
PATCH-250662018-08 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4343898)
PATCH-250672018-08 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4343898)
PATCH-250352018-08 Delta Update for Windows Server 2016 (1803) for x64-based Systems (KB4343909)
PATCH-250362018-08 Delta Update for Windows 10 Version 1803 for x86-based Systems (KB4343909)
PATCH-250372018-08 Delta Update for Windows 10 Version 1803 for x64-based Systems (KB4343909)
PATCH-250382018-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4343909)
PATCH-250392018-08 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4343909)
PATCH-250402018-08 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4343909)
PATCH-250292018-08 Delta Update for Windows Server 2016 (1709) for x64-based Systems (KB4343897)
PATCH-250302018-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4343897)
PATCH-250312018-08 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4343897)
PATCH-250322018-08 Delta Update for Windows 10 Version 1709 for x86-based Systems (KB4343897)
PATCH-250332018-08 Cumulative Update for Windows Server 2016 (1709) for x64-based Systems (KB4343897)
PATCH-250342018-08 Delta Update for Windows 10 Version 1709 for x64-based Systems (KB4343897)
PATCH-250622018-08 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4343900)
PATCH-250632018-08 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4343900)
PATCH-250642018-08 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4343900)
PATCH-25053Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4343205)
PATCH-25054Cumulative Security Update for Internet Explorer 10 for Windows Server 2012 (KB4343205)
PATCH-25055Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB4343205)
PATCH-25056Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB4343205)
PATCH-25057Cumulative Security Update for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB4343205)
PATCH-25058Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 (KB4343205)
PATCH-25059Cumulative Security Update for Internet Explorer 11 for Windows 7 (KB4343205)
PATCH-25060Cumulative Security Update for Internet Explorer 11 for Windows 7 for x64-based Systems (KB4343205)
PATCH-25061Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based Systems (KB4343205)
PATCH-250682018-08 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4343901)
PATCH-251622018-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4343897)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234