Description: | Summary: This host is missing an important security update according to Microsoft KB4056898
Vulnerability Insight: Multiple flaws exist due to:
- Multiple errors in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory.
- An error in the way that Windows handles objects in memory.
- Multiple errors in the way that the Windows Kernel API enforces permissions.
- An error in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine.
- Multiple errors in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass.
- Multiple errors leading to 'speculative execution side-channel attacks' that affect many modern processors and operating systems including Intel, AMD, and ARM.
Vulnerability Impact: Successful exploitation will allow an attacker to execute arbitrary code and take control of an affected system, gain access to sensitive data, cause a target system to stop responding, impersonate processes, interject cross-process communication, interrupt system functionality, bypass certain security checks and conduct bounds check bypass, branch target injection, rogue data cache load.
Affected Software/OS: - Microsoft Windows 8.1 for 32-bit/x64
- Microsoft Windows Server 2012 R2
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 7.1
CVSS Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
|