Description: | Summary: This host is missing a critical security update according to Microsoft KB4074588
Vulnerability Insight: Multiple flaws exist due to:
- Multiple errors in the way the scripting engine handles objects in memory in Microsoft browsers.
- An error when the Windows kernel fails to properly handle objects in memory.
- An error when the Windows kernel fails to properly initialize a memory address.
- An error when the Windows Common Log File System (CLFS) driver improperly handles objects in memory.
- An error when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user computer or data.
- An error when Storage Services improperly handles objects in memory.
- An error in Windows Scripting Host which could allow an attacker to bypass Device Guard.
- An error in StructuredQuery when the software fails to properly handle objects in memory.
- An error when NTFS improperly handles objects.
- An error when Named Pipe File System improperly handles objects.
- An error when AppContainer improperly implements constrained impersonation.
- An error as Microsoft has deprecated the Document Signing functionality in XPS Viewer.
- An error in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass.
Vulnerability Impact: Successful exploitation will allow an attacker to gain the same user rights as the current user, run arbitrary code in kernel mode, obtain information to further compromise the user, run processes in an elevated context, circumvent a User Mode Code Integrity (UMCI) policy on the machine, spoof content, perform phishing attacks, or otherwise manipulate content of a document.
Affected Software/OS: - Microsoft Windows 10 Version 1709 for 32-bit Systems
- Microsoft Windows 10 Version 1709 for 64-based Systems
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|