Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.811663
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft Office 2010 Service Pack 2 Multiple Vulnerabilities (KB3213638)
Zusammenfassung:This host is missing a critical security; update according to Microsoft KB3213638
Beschreibung:Summary:
This host is missing a critical security
update according to Microsoft KB3213638

Vulnerability Insight:
Multiple flaws exist due to:

- The way that the Windows Graphics Device Interface (GDI) handles objects in
memory, allowing an attacker to retrieve information from a targeted system.

- The Windows font library improperly handles specially crafted embedded
fonts.

- Windows Uniscribe improperly discloses the contents of its memory.

Vulnerability Impact:
Successful exploitation will allow an attacker
to retrieve information from a targeted system. By itself, the information
disclosure does not allow arbitrary code execution. However, it could allow
arbitrary code to be run if the attacker uses it in combination with another
vulnerability.

Affected Software/OS:
Microsoft Office 2010 Service Pack 2.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 100755
BugTraq ID: 100772
BugTraq ID: 100773
Common Vulnerability Exposure (CVE) ID: CVE-2017-8676
http://www.securityfocus.com/bid/100755
http://www.securitytracker.com/id/1039333
Common Vulnerability Exposure (CVE) ID: CVE-2017-8682
http://www.securityfocus.com/bid/100772
https://www.exploit-db.com/exploits/42744/
http://www.securitytracker.com/id/1039352
Common Vulnerability Exposure (CVE) ID: CVE-2017-8695
http://www.securityfocus.com/bid/100773
http://www.securitytracker.com/id/1039344
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.