Beschreibung: | Summary: This host is missing a critical security update according to Microsoft KB4093114
Vulnerability Insight: Multiple flaws exist due to errors,
- When the Windows font library improperly handles specially crafted embedded fonts.
- When Internet Explorer improperly accesses objects in memory.
- When the Windows kernel fails to properly initialize a memory address.
- When the scripting engine does not properly handle objects in memory in Internet Explorer.
- In Windows Adobe Type Manager Font Driver (ATMFD).
- In the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass.
- In the way that Windows SNMP Service handles malformed SNMP traps.
- In the way that the VBScript engine handles objects in memory.
- When Windows improperly handles objects in memory and incorrectly maps kernel memory.
- In the way that Windows handles objects in memory.
- In Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests.
- When Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system.
- In the Microsoft JET Database Engine that could allow remote code execution on an affected system.
Vulnerability Impact: Successful exploitation will allow an attacker to take control of the affected system, obtain information to further compromise the user's system, execute arbitrary code, retrieve the memory address of a kernel object, cause a target system to stop responding.
Affected Software/OS: - Microsoft Windows 8.1 for 32-bit/x64
- Microsoft Windows Server 2012 R2
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|