Beschreibung: | Summary: This host is missing a critical security update according to Microsoft KB4487018
Vulnerability Insight: Multiple flaws exist due to:
- Microsoft Server Message Block 2 server improperly handles certain requests.
- An error in Windows which could allow an attacker to bypass Device Guard.
- Windows Graphics Device Interface (GDI) improperly handles objects in the memory.
- Windows GDI component improperly discloses the contents of its memory.
- Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system.
- when Windows improperly discloses file information.
- Internet Explorer improperly handles objects in memory.
- Windows kernel fails to properly handle objects in memory.
- Microsoft browsers improperly handles specific redirects.
- The scripting engine handles objects in memory in Microsoft Edge.
- The Storage Service improperly handles file operations.
- Windows Jet Database Engine improperly handles objects in memory.
- Windows Server DHCP service improperly handle specially crafted packets to a DHCP server.
- Windows Win32k component fails to properly handle objects in memory.
- Windows kernel improperly handles objects in memory.
- The Human Interface Devices (HID) component improperly handles objects in memory.
- Internet Explorer improperly accesses objects in memory.
- Microsoft Edge improperly accesses objects in memory.
- The win32k component improperly provides kernel information.
Vulnerability Impact: Successful exploitation will allow an attacker to execute code on the target server, obtain information to further compromise the user's system, bypass security restriction and take control of the affected system.
Affected Software/OS: - Microsoft Windows 10 for 32-bit Systems
- Microsoft Windows 10 for x64-based Systems
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|