Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.811697
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Office Word Viewer Multiple Vulnerabilities (KB4011134)
Resumen:This host is missing a critical security; update according to Microsoft KB4011134
Descripción:Summary:
This host is missing a critical security
update according to Microsoft KB4011134

Vulnerability Insight:
Multiple flaws exist due to:

- An error in the way Windows Graphics Device Interface (GDI) handles objects
in memory,

- An error in the Windows font library which improperly handles specially
crafted embedded fonts.

- An error when Windows Uniscribe improperly discloses the contents of its
memory.

Vulnerability Impact:
Successful exploitation will allow an attacker
to retrieve information from a targeted system. By itself, the information
disclosure does not allow arbitrary code execution. However, it could allow
arbitrary code to be run if the attacker uses it in combination with another
vulnerability.

Affected Software/OS:
Microsoft Office Word Viewer.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-8676
BugTraq ID: 100755
http://www.securityfocus.com/bid/100755
http://www.securitytracker.com/id/1039333
Common Vulnerability Exposure (CVE) ID: CVE-2017-8682
BugTraq ID: 100772
http://www.securityfocus.com/bid/100772
https://www.exploit-db.com/exploits/42744/
http://www.securitytracker.com/id/1039352
Common Vulnerability Exposure (CVE) ID: CVE-2017-8695
BugTraq ID: 100773
http://www.securityfocus.com/bid/100773
http://www.securitytracker.com/id/1039344
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.