Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.811564
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Windows Multiple Vulnerabilities (KB4034668)
Resumen:This host is missing a critical security; update according to Microsoft KB4034668
Descripción:Summary:
This host is missing a critical security
update according to Microsoft KB4034668

Vulnerability Insight:
Multiple flaws exist due to:

- The Win32k component fails to properly handle objects in
memory.

- Windows Input Method Editor (IME) when IME improperly handles parameters in
a method of a DCOM class.

- The way that Microsoft browser JavaScript engines render content when
handling objects in memory.

- Microsoft browsers improperly access objects in memory.

- An error in Windows Error Reporting (WER).

- The way JavaScript engines render when handling objects in memory in
Microsoft browsers.

- Windows Hyper-V on a host server fails to properly validate input from an
authenticated user on a guest operating system.

- The Microsoft JET Database Engine that could allow remote code execution on
an affected system.

- Windows Search improperly handles objects in memory.

- Internet Explorer fails to validate User Mode Code Integrity (UMCI)
policies.

- Microsoft Edge improperly handles objects in memory.

- Microsoft Windows PDF Library improperly handles objects in memory.

- Microsoft Windows improperly handles NetBIOS packets.

Vulnerability Impact:
Successful exploitation will allow
an attacker who successfully exploited this vulnerability to run arbitrary
code in kernel mode, instantiate the DCOM class and exploit the system even if IME
is not enabled, gain access to sensitive information and system functionality and
cause denial of service condition.

Affected Software/OS:
- Microsoft Windows 10 for 32-bit Systems

- Microsoft Windows 10 for x64-based Systems

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-0174
BugTraq ID: 100038
http://www.securityfocus.com/bid/100038
http://www.securitytracker.com/id/1039109
Common Vulnerability Exposure (CVE) ID: CVE-2017-0250
BugTraq ID: 98100
http://www.securityfocus.com/bid/98100
http://www.securitytracker.com/id/1039090
Common Vulnerability Exposure (CVE) ID: CVE-2017-0293
BugTraq ID: 100039
http://www.securityfocus.com/bid/100039
http://www.securitytracker.com/id/1039092
Common Vulnerability Exposure (CVE) ID: CVE-2017-8591
BugTraq ID: 99430
http://www.securityfocus.com/bid/99430
http://www.securitytracker.com/id/1039097
Common Vulnerability Exposure (CVE) ID: CVE-2017-8593
BugTraq ID: 100032
http://www.securityfocus.com/bid/100032
http://www.securitytracker.com/id/1039105
Common Vulnerability Exposure (CVE) ID: CVE-2017-8620
BugTraq ID: 100034
http://www.securityfocus.com/bid/100034
https://threatpost.com/windows-search-bug-worth-watching-and-squashing/127434/
http://www.securitytracker.com/id/1039091
Common Vulnerability Exposure (CVE) ID: CVE-2017-8624
BugTraq ID: 100061
http://www.securityfocus.com/bid/100061
http://www.securitytracker.com/id/1039106
Common Vulnerability Exposure (CVE) ID: CVE-2017-8625
BugTraq ID: 100063
http://www.securityfocus.com/bid/100063
https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/
https://posts.specterops.io/umci-vs-internet-explorer-exploring-cve-2017-8625-3946536c6442
http://www.securitytracker.com/id/1039112
Common Vulnerability Exposure (CVE) ID: CVE-2017-8633
BugTraq ID: 100069
http://www.securityfocus.com/bid/100069
http://www.securitytracker.com/id/1039102
Common Vulnerability Exposure (CVE) ID: CVE-2017-8635
BugTraq ID: 100055
http://www.securityfocus.com/bid/100055
https://www.exploit-db.com/exploits/42471/
http://www.securitytracker.com/id/1039094
http://www.securitytracker.com/id/1039095
Common Vulnerability Exposure (CVE) ID: CVE-2017-8644
BugTraq ID: 100044
http://www.securityfocus.com/bid/100044
https://www.exploit-db.com/exploits/42459/
http://www.securitytracker.com/id/1039101
Common Vulnerability Exposure (CVE) ID: CVE-2017-8652
BugTraq ID: 100047
http://www.securityfocus.com/bid/100047
https://www.exploit-db.com/exploits/42445/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8653
BugTraq ID: 100059
http://www.securityfocus.com/bid/100059
Common Vulnerability Exposure (CVE) ID: CVE-2017-8655
BugTraq ID: 100027
http://www.securityfocus.com/bid/100027
Common Vulnerability Exposure (CVE) ID: CVE-2017-8664
BugTraq ID: 100085
http://www.securityfocus.com/bid/100085
http://www.securitytracker.com/id/1039093
Common Vulnerability Exposure (CVE) ID: CVE-2017-8666
BugTraq ID: 100089
http://www.securityfocus.com/bid/100089
Common Vulnerability Exposure (CVE) ID: CVE-2017-8669
BugTraq ID: 100068
http://www.securityfocus.com/bid/100068
Common Vulnerability Exposure (CVE) ID: CVE-2017-8672
BugTraq ID: 100072
http://www.securityfocus.com/bid/100072
Common Vulnerability Exposure (CVE) ID: CVE-2017-8636
BugTraq ID: 100056
http://www.securityfocus.com/bid/100056
https://www.exploit-db.com/exploits/42466/
https://www.exploit-db.com/exploits/42467/
https://www.exploit-db.com/exploits/42468/
https://www.exploit-db.com/exploits/42478/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8640
BugTraq ID: 100051
http://www.securityfocus.com/bid/100051
https://www.exploit-db.com/exploits/42476/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8641
BugTraq ID: 100057
http://www.securityfocus.com/bid/100057
https://www.exploit-db.com/exploits/42465/
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.