Description: | Summary: This host is missing a critical security update according to Microsoft KB4022727
Vulnerability Insight: Multiple flaws exist due to:
- Users cannot print enhanced metafiles (EMF) or documents containing bitmaps rendered out of bounds using the BitMapSection (DIBSection) function.
- Displays turn off unexpectedly even when 'Turn off display' is set to 'Never' in Power Options.
- certutil.exe can no longer generate an export file (.epf) when attempting to recover a key for a version 1 certificate.
- MSI files will no longer install when Device Guard is enabled.
- A thin client becomes unusable and unresponsive when Unified Write Filter (UWF) with DISK mode is enabled causing NTFS errors with ID: 55 & ID: 130 to be logged in the Event Logs.
- Microsoft Edge improperly accesses objects in memory.
Vulnerability Impact: Successful exploitation will allow attackers to gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs. View, change, or delete data, or create new accounts with full user rights.
Affected Software/OS: Microsoft Windows 10 for 32bit/x64-based Systems.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|