Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.811563
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Windows Multiple Vulnerabilities (KB4034672)
Resumen:This host is missing a critical security; update according to Microsoft KB4034672
Descripción:Summary:
This host is missing a critical security
update according to Microsoft KB4034672

Vulnerability Insight:
Multiple flaws exist due to:

- The Win32k component fails to properly handle objects in memory.

- Windows Input Method Editor (IME) when IME improperly handles parameters in
a method of a DCOM class.

- An error in Windows Error Reporting (WER).

- Windows Hyper-V on a host server fails to properly validate input from an
authenticated user on a guest operating system.

- Microsoft JET Database Engine that could allow remote code execution on
an affected system.

- Windows Search improperly handles objects in memory memory.

- Microsoft Windows PDF Library improperly handles objects in memory.

- Microsoft Windows improperly handles NetBIOS packets.

- The win32k component improperly provides kernel information.

- The Volume Manager Extension Driver component improperly provides
kernel information.

Vulnerability Impact:
Successful exploitation will allow an attacker
to run arbitrary code in kernel mode, instantiate the DCOM class and exploit the
system even if IME is not enabled, gain access to sensitive information and
system functionality, take complete control of an affected system, cause denial
of service condition and further compromise the user's system.

Affected Software/OS:
- Microsoft Windows Server 2012 R2

- Microsoft Windows 8.1 for 32-bit/x64

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-0174
BugTraq ID: 100038
http://www.securityfocus.com/bid/100038
http://www.securitytracker.com/id/1039109
Common Vulnerability Exposure (CVE) ID: CVE-2017-0250
BugTraq ID: 98100
http://www.securityfocus.com/bid/98100
http://www.securitytracker.com/id/1039090
Common Vulnerability Exposure (CVE) ID: CVE-2017-0293
BugTraq ID: 100039
http://www.securityfocus.com/bid/100039
http://www.securitytracker.com/id/1039092
Common Vulnerability Exposure (CVE) ID: CVE-2017-8591
BugTraq ID: 99430
http://www.securityfocus.com/bid/99430
http://www.securitytracker.com/id/1039097
Common Vulnerability Exposure (CVE) ID: CVE-2017-8593
BugTraq ID: 100032
http://www.securityfocus.com/bid/100032
http://www.securitytracker.com/id/1039105
Common Vulnerability Exposure (CVE) ID: CVE-2017-8620
BugTraq ID: 100034
http://www.securityfocus.com/bid/100034
https://threatpost.com/windows-search-bug-worth-watching-and-squashing/127434/
http://www.securitytracker.com/id/1039091
Common Vulnerability Exposure (CVE) ID: CVE-2017-8624
BugTraq ID: 100061
http://www.securityfocus.com/bid/100061
http://www.securitytracker.com/id/1039106
Common Vulnerability Exposure (CVE) ID: CVE-2017-8633
BugTraq ID: 100069
http://www.securityfocus.com/bid/100069
http://www.securitytracker.com/id/1039102
Common Vulnerability Exposure (CVE) ID: CVE-2017-8664
BugTraq ID: 100085
http://www.securityfocus.com/bid/100085
http://www.securitytracker.com/id/1039093
Common Vulnerability Exposure (CVE) ID: CVE-2017-8666
BugTraq ID: 100089
http://www.securityfocus.com/bid/100089
Common Vulnerability Exposure (CVE) ID: CVE-2017-8668
BugTraq ID: 100092
http://www.securityfocus.com/bid/100092
http://www.securitytracker.com/id/1039108
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.