Description: | Summary: This host is missing a critical security update according to Microsoft KB4034665
Vulnerability Insight: Multiple flaws exist due to:
- The Win32k component fails to properly handle objects in memory.
- Input Method Editor (IME) when IME improperly handles parameters in a method of a DCOM class.
- When Microsoft browsers improperly access objects in memory.
- When handling objects in memory in microsoft browsers.
- When Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system.
- Microsoft JET Database Engine that could allow remote code execution on an affected system.
- When Windows Search handles objects in memory.
- The way that Microsoft browser JavaScript engines render content when handling objects in memory.
- When Internet Explorer improperly accesses objects in memory.
Vulnerability Impact: Successful exploitation will allow an attacker to run arbitrary code in kernel mode, gain access to sensitive information and system functionality, also can gain the same user rights as the current user and obtain information to further compromise the user's system.
Affected Software/OS: Microsoft Windows Server 2012.
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|