Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810921
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Scripting Engine Remote Code Execution Vulnerability (KB4015067)
Summary:This host is missing an important security; update according to Microsoft April 2017 Security Update KB4015067.
Description:Summary:
This host is missing an important security
update according to Microsoft April 2017 Security Update KB4015067.

Vulnerability Insight:
The flaw exists in the way that the
VBScript engine handles objects in memory.

Vulnerability Impact:
Successful exploitation will allow an attacker
to gain the same user rights as the current user. If the current user is logged
on with administrative user rights, an attacker who successfully exploited this
vulnerability could take complete control of an affected system. An attacker
could then install programs, view, change, delete data, or create new
accounts with full user rights.

Affected Software/OS:
- Microsoft Windows Vista x32/x64 Edition Service Pack 2

- Microsoft Windows Server 2008 x32/x64 Edition Service Pack 2

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-0158
BugTraq ID: 97455
http://www.securityfocus.com/bid/97455
http://www.securitytracker.com/id/1038238
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.