Description: | Summary: This host is missing a critical security update according to Microsoft KB4034664
Vulnerability Insight: Multiple flaws exist due to:
- The Win32k component fails to properly handle objects in memory.
- Windows Error Reporting (WER).
- Improperly accessing objects in memory.
- Windows font library improperly handles specially crafted embedded fonts.
- The Microsoft JET Database Engine that could allow remote code execution on an affected system.
- Windows Search handles objects in memory.
- The way that Microsoft browser JavaScript engines render content when handling objects in memory.
- When the win32k component improperly provides kernel information.
- When the Volume Manager Extension Driver component improperly provides kernel information.
Vulnerability Impact: Successful exploitation will allow an attacker to run arbitrary code in kernel mode, gain access to sensitive information and system functionality, gain the same user rights as the current user and obtain information to further compromise the user's system.
Affected Software/OS: - Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Microsoft Windows 7 for 32-bit/x64 Systems Service Pack 1
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|