Beschreibung: | Summary: This host is missing a critical security update according to Microsoft KB4025338
Vulnerability Insight: Multiple flaws exist due to:
- Microsoft Windows when Win32k fails to properly handle objects in memory.
- The way that the Scripting Engine renders when handling objects in memory in Microsoft browsers.
- The way JavaScript engines render when handling objects in memory in Microsoft browsers.
- The way Microsoft Edge handles objects in memory.
- When Windows Explorer improperly handles executable files and shares during rename operations.
- when an affected Microsoft browser does not properly parse HTTP content.
- when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
- When Kerberos falls back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol.
- The way that the Windows Kernel handles objects in memory.
- The Microsoft Graphics Component fails to properly handle objects in memory.
Vulnerability Impact: Successful exploitation will allow an attacker who successfully exploited the vulnerability to gain the same user rights as the current user, run arbitrary code, processes with elevated privileges. Also could take control of the affected system and cause denial of service.
Affected Software/OS: Microsoft Windows 10 for x86/x64-based Systems.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|