Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.815490
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Multiple Vulnerabilities (KB4520005)
Summary:This host is missing a critical security; update according to Microsoft KB4520005
Description:Summary:
This host is missing a critical security
update according to Microsoft KB4520005

Vulnerability Insight:
Multiple flaws exist due to:

- Microsoft Browsers does not properly parse HTTP content.

- Microsoft XML Core Services MSXML parser processes user input.

- A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle
attacker is able to successfully bypass the NTLM MIC (Message Integrity Check)
protection.

- An error in windows redirected drive buffering system (rdbss.sys) when the
operating system improperly handles specific local calls.

- Windows Error Reporting (WER) improperly handles and executes files.

- Windows Error Reporting manager improperly handles hard links.

- Remote Desktop Protocol (RDP) improperly handles connection requests.

- Windows Code Integrity Module improperly handles objects in memory.

- Windows Jet Database Engine improperly handles objects in memory.

Please see the references for more information about the vulnerabilities.

Vulnerability Impact:
Successful exploitation will allow an attacker
to run arbitrary code on the client machine, bypass security restrictions,
elevate privileges and read privileged data across trust boundaries, create a
denial of service condition and conduct spoofing attack.

Affected Software/OS:
- Microsoft Windows 8.1 for 32-bit/x64-based systems

- Microsoft Windows Server 2012 R2

Solution:
The vendor has released updates. Please see
the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-0608
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0608
Common Vulnerability Exposure (CVE) ID: CVE-2019-1060
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1060
Common Vulnerability Exposure (CVE) ID: CVE-2019-1166
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1166
Common Vulnerability Exposure (CVE) ID: CVE-2019-1192
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1192
Common Vulnerability Exposure (CVE) ID: CVE-2019-1238
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1238
Common Vulnerability Exposure (CVE) ID: CVE-2019-1311
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1311
Common Vulnerability Exposure (CVE) ID: CVE-2019-1315
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1315
Common Vulnerability Exposure (CVE) ID: CVE-2019-1318
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1318
Common Vulnerability Exposure (CVE) ID: CVE-2019-1319
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1319
Common Vulnerability Exposure (CVE) ID: CVE-2019-1325
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1325
Common Vulnerability Exposure (CVE) ID: CVE-2019-1326
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1326
Common Vulnerability Exposure (CVE) ID: CVE-2019-1333
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333
Common Vulnerability Exposure (CVE) ID: CVE-2019-1334
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1334
Common Vulnerability Exposure (CVE) ID: CVE-2019-1339
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1339
Common Vulnerability Exposure (CVE) ID: CVE-2019-1341
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1341
Common Vulnerability Exposure (CVE) ID: CVE-2019-1342
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1342
Common Vulnerability Exposure (CVE) ID: CVE-2019-1343
http://packetstormsecurity.com/files/154798/Microsoft-Windows-Kernel-nt-MiOffsetToProtos-NULL-Pointer-Dereference.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1343
Common Vulnerability Exposure (CVE) ID: CVE-2019-1344
http://packetstormsecurity.com/files/154799/Microsoft-Windows-Kernel-CI-CipFixImageType-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1344
Common Vulnerability Exposure (CVE) ID: CVE-2019-1346
http://packetstormsecurity.com/files/154801/Microsoft-Windows-Kernel-CI-HashKComputeFirstPageHash-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1346
Common Vulnerability Exposure (CVE) ID: CVE-2019-1347
http://packetstormsecurity.com/files/154802/Microsoft-Windows-Kernel-nt-MiRelocateImage-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1347
Common Vulnerability Exposure (CVE) ID: CVE-2019-1357
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1357
Common Vulnerability Exposure (CVE) ID: CVE-2019-1358
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1358
Common Vulnerability Exposure (CVE) ID: CVE-2019-1359
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1359
Common Vulnerability Exposure (CVE) ID: CVE-2019-1365
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1365
Common Vulnerability Exposure (CVE) ID: CVE-2019-1367
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1367
Common Vulnerability Exposure (CVE) ID: CVE-2019-1371
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1371
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.