Descripción: | Summary: This host is missing a critical security update according to Microsoft KB4471327
Vulnerability Insight: Multiple flaws exist due to:
- Windows kernel fails to properly handle objects in memory.
- Chakra scripting engine improperly handles objects in memory in Microsoft Edge.
- Connected User Experiences and Telemetry Service fails to validate certain function values.
- Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions.
- Windows GDI component improperly discloses the contents of its memory.
- Scripting engine improperly handles objects in memory in Internet Explorer.
- VBScript engine improperly handles objects in memory.
- Windows kernel-mode driver fails to properly handle objects in memory.
- Internet Explorer improperly accesses objects in memory.
- Windows Win32k component fails to properly handle objects in memory.
- Microsoft text-to-speech fails to properly handle objects in the memory.
- Diagnostics Hub Standard Collector Service improperly impersonates certain file operations.
- Remote Procedure Call runtime improperly initializes objects in memory.
Vulnerability Impact: Successful exploitation will allow an attacker to run arbitrary code in kernel mode, obtain sensitive information, deny dependent security feature functionality, gain elevated privileges and could take control of the affected system.
Affected Software/OS: Microsoft Windows 10 Version 1703 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|