Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.811492
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Security Essentials Remote Code Execution Vulnerability (Jul 2017)
Resumen:Security Essentials is prone to a remote code execution (RCE) vulnerability.
Descripción:Summary:
Security Essentials is prone to a remote code execution (RCE) vulnerability.

Vulnerability Insight:
The flaw exists as the Microsoft Malware
Protection Engine does not properly scan a specially crafted file leading to
memory corruption.

Vulnerability Impact:
Successful exploitation will allow an attacker
to execute arbitrary code in the security context of the LocalSystem account and
take control of the system. An attacker could then install programs. View, change,
or delete data or create new accounts with full user rights.

Affected Software/OS:
Microsoft Security Essentials.

Solution:
Microsoft Malware Protection Engine's built-in
mechanism for the automatic detection and deployment of updates will apply the
update within 48 hours of release.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-8558
BugTraq ID: 99262
http://www.securityfocus.com/bid/99262
https://www.exploit-db.com/exploits/42264/
http://www.securitytracker.com/id/1038783
http://www.securitytracker.com/id/1038784
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.