Description: | Summary: This host is missing a critical security update according to Microsoft KB4056892.
Vulnerability Insight: Multiple flaws exist due to:
- Microsoft Edge does not properly enforce cross-domain policies.
- The scripting engine handles objects in memory in Microsoft Edge.
- The scripting engine handles objects in memory in Microsoft browsers.
- Windows Adobe Type Manager Font Driver (ATMFD.dll) fails to properly handle objects in memory.
- Microsoft Edge PDF Reader improperly handles objects in memory.
- Windows kernel fails to properly handle objects in memory.
- An error in the way that the Windows Kernel API enforces permissions.
- An error in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine.
- An error in the Windows kernel.
- Multiple errors leading to 'speculative execution side-channel attacks' that affect many modern processors and operating systems including Intel, AMD, and ARM.
- An integer overflow in Windows Subsystem for Linux.
- .NET, and .NET core, improperly process XML documents.
- Microsoft .NET Framework (and .NET Core) components do not completely validate certificates.
Vulnerability Impact: Successful exploitation will allow an attacker to elevate privileges, execute arbitrary code in the context of the current user, potentially read data that was not intended to be disclosed, impersonate processes, interject cross-process communication, or interrupt system functionality, bypass certain security checks in the operating system and can cause a target system to stop responding and can be used to read the content of memory across a trusted boundary and can therefore lead to information disclosure and some unspecified impacts too.
Affected Software/OS: Microsoft Windows 10 Version 1709 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 7.6
CVSS Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C
|