Description: | Summary: This host is missing a critical security update according to Microsoft Bulletin MS16-085.
Vulnerability Insight: Multiple flaws exist due to:
- A security feature bypass exists when Microsoft Edge does not properly implement Address Space Layout Randomization (ASLR).
- Multiple remote code execution vulnerabilities exist when Microsoft Edge improperly accesses objects in memory.
- Multiple remote code execution vulnerabilities exist in the way that the Chakra JavaScript engine renders when handling objects in memory
- A spoofing vulnerability exists when a Microsoft browser does not properly parse HTTP content.
- A spoofing vulnerability exists when the Microsoft Browser in reader mode does not properly parse HTML content.
- An information disclosure vulnerability exists when the Microsoft Browser improperly handles objects in memory.
Vulnerability Impact: Successful exploitation will allow remote attackers to trick a user into loading a page containing malicious content, to trick the user into opening the .pdf file and read information in the context of the current user and to execute arbitrary code.
Affected Software/OS: - Microsoft Windows 10 x32/x64
- Microsoft Windows 10 Version 1511 x32/x64
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|