Description: | Summary: This host is missing a critical security update according to Microsoft KB4486563
Vulnerability Insight: Multiple flaws exist due to:
- Windows Jet Database Engine improperly handles objects in memory.
- Human Interface Devices (HID) component improperly handles objects in memory.
- Windows GDI component improperly discloses the contents of its memory.
- Internet Explorer improperly accesses objects in memory.
- Windows kernel improperly handles objects in memory.
- Win32k component fails to properly handle objects in memory.
- DHCP servers fails to properly handle network packets.
- Microsoft Server Message Block 2.0 (SMBv2) server improperly handles specially crafted requests.
- Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system.
- Microsoft browsers improperly handles specific redirects.
- Internet Explorer improperly handles objects in memory.
Vulnerability Impact: Successful exploitation will allow an attacker to execute arbitrary code on a victim system, obtain information to further compromise the user's system, gain elevated privileges and conduct spoofing attacks.
Affected Software/OS: - Microsoft Windows 7 for 32-bit/x64 Systems Service Pack 1
- Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|