Beschreibung: | Summary: This host is missing an important security update according to Microsoft KB4056897
Vulnerability Insight: Multiple flaws exist due to:
- Multiple errors in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory.
- An error in the Windows GDI component which improperly discloses kernel memory addresses.
- An error in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine.
- An error in the way that the Windows Kernel API enforces permissions.
- An error in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass.
- An error in the way that the Color Management Module (ICM32.dll) handles objects in memory.
- Multiple errors leading to 'speculative execution side-channel attacks' that affect many modern processors and operating systems including Intel, AMD, and ARM.
Vulnerability Impact: Successful exploitation will allow an attacker to execute arbitrary code and take control of an affected system, elevate their user rights, gain access to sensitive data, bypass certain security checks, impersonate processes, interject cross-process communication, interrupt system functionality and conduct bounds check bypass, branch target injection, rogue data cache load.
Affected Software/OS: - Microsoft Windows 7 for 32-bit/x64 Systems Service Pack 1
- Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 6.9
CVSS Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
|