Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.811028
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft Windows 'Win32k.sys' Multiple Vulnerabilities (KB4019204)
Zusammenfassung:This host is missing an important security; update according to Microsoft security update KB4019204.
Beschreibung:Summary:
This host is missing an important security
update according to Microsoft security update KB4019204.

Vulnerability Insight:
Multiple flaws are due to:

- An error when the win32k component improperly provides kernel information.

- An error when Windows improperly handles objects in memory.

- An error in Windows when the Windows kernel-mode driver fails to properly
handle objects in memory.

Vulnerability Impact:
Successful exploitation will allow an attacker
to run arbitrary code in kernel mode allowing attacker to install programs,
view, change, or delete data, or create new accounts with full user rights.Also
an attacker who successfully exploited this vulnerability could run processes
in an elevated context and can lead to denial of service condition as well.This
vulnerability also could allow attacker obtain sensitive information to further
compromise the user's system.

Affected Software/OS:
- Microsoft Windows XP SP2 x64

- Microsoft Windows XP SP3 x86

- Microsoft Windows Vista x32/x64 Edition Service Pack 2

- Microsoft Windows 2003 x32/x64 Edition Service Pack 2 and prior

- Microsoft Windows Server 2008 x32/x64 Edition Service Pack 2 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-0245
BugTraq ID: 98115
http://www.securityfocus.com/bid/98115
https://www.exploit-db.com/exploits/42008/
Common Vulnerability Exposure (CVE) ID: CVE-2017-0246
BugTraq ID: 98108
http://www.securityfocus.com/bid/98108
http://www.securitytracker.com/id/1038449
Common Vulnerability Exposure (CVE) ID: CVE-2017-0263
BugTraq ID: 98258
http://www.securityfocus.com/bid/98258
https://www.exploit-db.com/exploits/44478/
https://xiaodaozhi.com/exploit/117.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-8552
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.