Description: | Summary: This host is missing a critical security update according to Microsoft KB4053580
Vulnerability Insight: Multiple flaws exist due to:
- An error in RPC if the server has Routing and Remote Access enabled.
- An error when Internet Explorer improperly accesses objects in memory.
- An error when Internet Explorer improperly handles objects in memory.
- An error when the Windows its:// protocol handler unnecessarily sends traffic to a remote site in order to determine the zone of a provided URL.
- An error when Microsoft Edge improperly accesses objects in memory.
- An error in the way that the scripting engine handles objects in memory in Microsoft Edge.
- An error in the way the scripting engine handles objects in memory in Microsoft browsers.
- A security feature bypass exists when Device Guard incorrectly validates an untrusted file.
Vulnerability Impact: Successful exploitation will allow an attacker to execute arbitrary code, gain the same user rights as the current user, obtain sensitive information to further compromise the user's system, a brute-force to disclose the NTLM hash password and make an unsigned file appear to be signed.
Affected Software/OS: Microsoft Windows 10 Version 1703 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 8.5
CVSS Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C
|