Microsoft Edge and Internet Explorer Type Confusion Vulnerability
Microsoft Internet Explorer 10 및 11과 Microsoft Edge의 mshtml.dll 내 Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement 함수에는 타입 혼동 문제가 있으며, 이로 인해 원격 공격자가 조작된 Cascading Style Sheets (CSS) 토큰 시퀀스 및 TH 요소에 작용하는 조작된 JavaScript 코드와 관련된 벡터를 통해 임의 코드를 실행할 수 있습니다.
Microsoft Internet Explorer 10 및 11과 Microsoft Edge의 mshtml.dll 내 Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement 함수에는 타입 혼동 문제가 있으며, 이로 인해 원격 공격자가 조작된 Cascading Style Sheets (CSS) 토큰 시퀀스 및 TH 요소에 작용하는 조작된 JavaScript 코드와 관련된 벡터를 통해 임의 코드를 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.
영향 제품·버전
제품 Microsoft Edge and Internet Explorer
영향 버전 Microsoft Edge and Internet Explorer Internet Explorer 10 and 11 and Edge, 11
Microsoft Edge and Internet Explorer의 현재 전체 버전이 공식 영향 범위(Microsoft Edge and Internet Explorer Internet Explorer 10 and 11 and Edge, 11)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply updates per vendor instructions.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 유형 미확정 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.