Description: | Summary: This host is missing a critical security update according to Microsoft KB4074594
Vulnerability Insight: Multiple flaws exist due to:
- The scripting engine fails to properly handles objects in memory in microsoft browsers.
- The windows kernel fails to properly handle objects in memory.
- The Windows Common Log File System (CLFS) driver improperly handles objects in memory.
- The VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data.
- An improper implementation of the Microsoft Server Message Block 2.
- Microsoft has deprecated the Document Signing functionality in XPS Viewer.
Vulnerability Impact: Successful exploitation will allow an attacker who successfully exploited the vulnerability gain the same user rights as the current user, run arbitrary code in kernel mode, obtain information to further compromise the user's system, cause the affected system to stop responding until it is manually restarted, spoof content, perform phishing attacks, or otherwise manipulate content of a document.
Affected Software/OS: - Microsoft Windows 8.1 for 32-bit/x64
- Microsoft Windows Server 2012 R2
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|