Description: | Summary: This host is missing a critical security update according to Microsoft KB4022715
Vulnerability Insight: Multiple flaws exist due to:
- The way JavaScript engines render when handling objects in memory in Microsoft browsers.
- The way the Microsoft Edge JavaScript scripting engine handles objects in memory.
- Windows kernel improperly initializes objects in memory.
- Windows improperly handles objects in memory.
- Windows Search improperly handles objects in memory.
- Windows Secure Kernel Mode fails to properly handle objects in memory.
- Microsoft Edge Fetch API incorrectly handles a filtered response type.
- Windows GDI component improperly discloses the contents of its memory.
- Microsoft scripting engines do not properly handle objects in memory.
- Microsoft Edge improperly accesses objects in memory.
For more information please check the Reference URL.
Vulnerability Impact: Successful exploitation will allow attackers to execute arbitrary code in the context of the current user, obtain sensitive information to further compromise the user's system and to bypass security.
Affected Software/OS: - Microsoft Windows 10 Version 1607 x32/x64
- Microsoft Windows Server 2016
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|