CVE-2017-8602
published 2017-07-11CVE-2017-8602: Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607…
PriorityP333medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
5.33%
91.7th percentile
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc2.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cp54-fjgm-8hr7: Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17
CVE-2017-8602 [MEDIUM] CWE-20 GHSA-cp54-fjgm-8hr7: Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
Microsoft
Microsoft Browser Spoofing Vulnerability
vendor_msrc·2017-07-11·CVSS 2.4
CVE-2017-8602 [MEDIUM] Microsoft Browser Spoofing Vulnerability
Microsoft Browser Spoofing Vulnerability
Description: A spoofing vulnerability exists when Microsoft browsers do not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
To exploit the vulnerability, the user must click a specially crafted URL. In an email attack scenario, an attacker could send an email message containing the specially crafted URL to the user in an attempt to convince the user to click it.
In a web-based attack scenario, an attacker could host a specially crafted website designed to appear as a legitimate website to the user.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2017
blogs_talos·2017-07-11·CVSS 7.8
CVE-2017-8463 [HIGH] Microsoft Patch Tuesday - July 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 54 vulnerabilities with 19 of them rated critical, 32 rated important, and 3 rated moderate. Impacted products include Edge, .NET Framework, Internet Explorer, Office, and Windows.
### Vulnerabilities Rated Critical
#### CVE-2017-8463
This is a remote code execution vulnerability related to the way that Windows Explorer handles executable files and shares during rename operations. If exploited this vulnerability could run arbitrary code, users not running as administrators would be less affected. This vulnerability can be triggered via a malicious share folder and malware named with an executable extension.
#### CVE-2017-8584 A remote code execution vul
Bugzilla
CVE-2016-8602 ghostscript: check for sufficient params in .sethalftone5
bugzilla·2016-10-12·CVSS 7.8
CVE-2016-8602 [HIGH] CVE-2016-8602 ghostscript: check for sufficient params in .sethalftone5
CVE-2016-8602 ghostscript: check for sufficient params in .sethalftone5
If you call .sethalftone5 with an empty operand stack, ghostscript crashes. This flaw could be exploitable
Upstream bug :
- Bug 697203 - NULL dereference in .sethalftone5
http://bugs.ghostscript.com/show_bug.cgi?id=697203
Upstream patch :
- Bug 697203: check for sufficient params in .sethalftone5
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=f5c7555c303
Reference :
http://seclists.org/oss-sec/2016/q4/98
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1383941]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0014 https://rhn.redhat.com/errata/RHSA-2017-0014.html
---
This issue has been addressed in the fo
http://www.securityfocus.com/bid/99390http://www.securitytracker.com/id/1038859http://www.securitytracker.com/id/1038860https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8602http://www.securityfocus.com/bid/99390http://www.securitytracker.com/id/1038859http://www.securitytracker.com/id/1038860https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8602
2017-07-11
Published