Descripción: | Summary: This host is missing a critical security update according to Microsoft KB4041689
Vulnerability Insight: Multiple flaws exist due to:
- A spoofing vulnerability in the Windows implementation of wireless networking (KRACK)
- The Universal CRT _splitpath was not handling multi byte strings correctly, which caused apps to fail when accessing multi byte filenames.
- The Universal CRT caused the linker (link.exe) to stop working for large projects.
- The MSMQ performance counter (MSMQ Queue) may not populate queue instances when the server hosts a clustered MSMQ role.
- The Lock Workstation policy for smart cards where, in some cases, the system doesn't lock when you remove the smart card.
- Issue with form submissions in Internet Explorer.
- Issue with URL encoding in Internet Explorer.
- Issue that prevents an element from receiving focus in Internet Explorer.
- Issue with the docking and undocking of Internet Explorer windows.
- Issue with the rendering of a graphics element in Internet Explorer.
- Issue caused by a pop-up window in Internet Explorer.
Vulnerability Impact: Successful exploitation will allow an attacker to run arbitrary code in the security context of the local system, take complete control of an affected system, bypass certain security restrictions, gain access to potentially sensitive information, conduct a denial-of-service condition and gain privileged access.
Affected Software/OS: Microsoft Windows 10 Version 1511 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|