Beschreibung: | Summary: This host is missing a critical security update according to Microsoft KB4056891
Vulnerability Insight: Multiple flaws exist due to:
- Microsoft Edge does not properly enforce cross-domain policies.
- The scripting engine handles objects in memory in Microsoft Edge.
- The scripting engine handles objects in memory in Microsoft Browsers.
- Windows Adobe Type Manager Font Driver (ATMFD.dll) fails to properly handle objects in memory.
- Microsoft Edge PDF Reader improperly handles objects in memory.
- Windows kernel fails to properly handle objects in memory.
- An error in the way that the Windows Kernel API enforces permissions.
- An error in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine.
- An error in the Windows kernel.
- An integer overflow in Windows Subsystem for Linux.
- Multiple errors leading to 'speculative execution side-channel attacks' that affect many modern processors and operating systems including Intel, AMD, and ARM.
- Microsoft .NET Framework (and .NET Core) components do not completely validate certificates.
- .NET, and .NET core, improperly process XML documents.
Vulnerability Impact: Successful exploitation will allow an attacker to elevate privileges, execute arbitrary code in the context of the current user, potentially read data that was not intended to be disclosed, impersonate processes, interject cross-process communication, or interrupt system functionality, bypass certain security checks in the operating system and can cause a target system to stop responding and conduct bounds check bypass, branch target injection, rogue data cache load.
Affected Software/OS: Microsoft Windows 10 Version 1703 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 7.6
CVSS Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C
|