#VU21633 Input validation error in Microsoft Internet Explorer and Microsoft Edge - CVE-2019-1357


Vulnerability identifier: #VU21633

Vulnerability risk: Medium

CVSSv4.0: 1.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2019-1357

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Microsoft Internet Explorer
Client/Desktop applications / Web browsers
Microsoft Edge
Client/Desktop applications / Web browsers

Vendor: Microsoft

Description

The vulnerability allows a remote attacker to spoofing attack.

The vulnerability exists due to insufficient validation of browser cookies. A remote attacker can send a specially crafted HTTP response and overwrite a secure cookie with an insecure one. This can be used to construct an attack chain against applications that rely on cookie security.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Microsoft Internet Explorer: 10 - 11

Microsoft Edge: All versions


External links
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1357


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability