Beschreibung: | Summary: This host is missing a critical security update according to Microsoft KB4525237
Vulnerability Insight: Multiple flaws exist due to:
- Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system.
- Windows Installer improperly handles certain filesystem operations.
- Windows Error Reporting (WER) improperly handles objects in memory.
- Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets.
- The win32k component improperly provides kernel information.
- Windows Universal Plug and Play (UPnP) service improperly allows COM object creation.
- Windows Jet Database Engine improperly handles objects in memory.
- Windows Graphics Component improperly handles objects in memory.
- Scripting engine improperly handles objects in memory in Microsoft Edge (HTML-based).
Please see the references for more information about the vulnerabilities.
Vulnerability Impact: Successful exploitation will allow an attacker to crash host server, execute code with elevated permissions, obtain information to further compromise the user's system, elevate privileges on an affected system and bypass security restrictions.
Affected Software/OS: - Microsoft Windows 10 Version 1803 for 32-bit Systems
- Microsoft Windows 10 Version 1803 for x64-based Systems
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|