Description: | Summary: This host is missing a critical security update according to Microsoft KB4022714
Vulnerability Insight: Multiple flaws exist due to:
- The metafiles (EMF) or documents containing bitmaps rendered out of bounds using the BitMapSection(DIBSection) function.
- The certutil.exe can no longer generate an export file (.epf) when attempting to recover a key for a version 1 certificate.
- Additional issues with updated time zone information, updates to the Access Point Name (APN) database and Internet Explorer. Security updates to Microsoft Scripting Engine, Microsoft Edge, Windows COM, Windows kernel, Windows kernel-mode drivers, Microsoft Uniscribe, Microsoft Graphics Component, Windows Shell, Microsoft Windows PDF and Internet Explorer. For more information about the security vulnerabilities resolved, please refer to the Security Update Guide.
- Microsoft Edge improperly accesses objects in memory.
Vulnerability Impact: Successful exploitation will allow attackers to execute arbitrary code in the context of the current user, gain the same user rights as the current user, to take control of an affected system.
Affected Software/OS: Microsoft Windows 10 Version 1511 x32/x64.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|