Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810909
Category:Windows : Microsoft Bulletins
Title:Microsoft Silverlight Multiple Remote Code Execution Vulnerabilities (KB4023307)
Summary:This host is missing an important security; update according to Microsoft security update KB4023307.
Description:Summary:
This host is missing an important security
update according to Microsoft security update KB4023307.

Vulnerability Insight:
Multiple flaws exist due to:

- The Windows font library improperly handles specially crafted embedded fonts.

- The way Windows Uniscribe handles objects in memory.

Vulnerability Impact:
Successful exploitation allows an attacker
to take control of the affected system. An attacker could then install
programs. View, change, or delete data or create new accounts with full user
rights.

Affected Software/OS:
Microsoft Silverlight version 5.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-0283
BugTraq ID: 98920
http://www.securityfocus.com/bid/98920
https://www.exploit-db.com/exploits/42234/
https://0patch.blogspot.com/2017/07/0patching-quick-brown-fox-of-cve-2017.html
https://bugs.chromium.org/p/project-zero/issues/detail?id=1198
http://www.securitytracker.com/id/1038675
Common Vulnerability Exposure (CVE) ID: CVE-2017-8527
BugTraq ID: 98933
http://www.securityfocus.com/bid/98933
http://www.securitytracker.com/id/1038680
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.