Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.815486
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Multiple Vulnerabilities (KB4520011)
Summary:This host is missing a critical security; update according to Microsoft KB4520011
Description:Summary:
This host is missing a critical security
update according to Microsoft KB4520011

Vulnerability Insight:
Multiple flaws exist due to:

- Speculative execution side channel vulnerabilities known as Microarchitectural
Data Sampling.

- Microsoft Browsers does not properly parse HTTP content.

- Chakra scripting engine improperly handles objects in memory in Microsoft Edge.

- Windows Imaging API improperly handles objects in memory.

- The 'umpo.dll' of the Power Service, improperly handles a Registry Restore
Key function.

- Windows Error Reporting manager improperly handles hard links.

- Internet Explorer improperly accesses objects in memory.

Please see the references for more information about the vulnerabilities.

Vulnerability Impact:
Successful exploitation will allow an attacker
to run arbitrary code on the client machine, elevate privileges and read
privileged data across trust boundaries, create a denial of service condition
and conduct spoofing attack.

Affected Software/OS:
- Microsoft Windows 10 for x64-based Systems

- Microsoft Windows 10 for 32-bit Systems

Solution:
The vendor has released updates. Please see
the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-12126
Bugtraq: 20190624 [SECURITY] [DSA 4447-2] intel-microcode security update (Google Search)
https://seclists.org/bugtraq/2019/Jun/28
Bugtraq: 20190624 [SECURITY] [DSA 4469-1] libvirt security update (Google Search)
https://seclists.org/bugtraq/2019/Jun/36
Bugtraq: 20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (Google Search)
https://seclists.org/bugtraq/2019/Nov/16
Bugtraq: 20191112 [SECURITY] [DSA 4564-1] linux security update (Google Search)
https://seclists.org/bugtraq/2019/Nov/15
Bugtraq: 20200114 [SECURITY] [DSA 4602-1] xen security update (Google Search)
https://seclists.org/bugtraq/2020/Jan/21
Debian Security Information: DSA-4602 (Google Search)
https://www.debian.org/security/2020/dsa-4602
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OH73SGTJ575OBCPSJFX6LX7KP2KZIEN4/
FreeBSD Security Advisory: FreeBSD-SA-19:07
https://www.freebsd.org/security/advisories/FreeBSD-SA-19:07.mds.asc
https://security.FreeBSD.org/advisories/FreeBSD-SA-19:26.mcu.asc
https://security.gentoo.org/glsa/202003-56
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html
https://lists.debian.org/debian-lts-announce/2019/06/msg00018.html
RedHat Security Advisories: RHSA-2019:1455
https://access.redhat.com/errata/RHSA-2019:1455
RedHat Security Advisories: RHSA-2019:2553
https://access.redhat.com/errata/RHSA-2019:2553
SuSE Security Announcement: openSUSE-SU-2019:1505 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00014.html
SuSE Security Announcement: openSUSE-SU-2019:1805 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00053.html
SuSE Security Announcement: openSUSE-SU-2019:1806 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00052.html
https://usn.ubuntu.com/3977-3/
Common Vulnerability Exposure (CVE) ID: CVE-2018-12127
Common Vulnerability Exposure (CVE) ID: CVE-2018-12130
Common Vulnerability Exposure (CVE) ID: CVE-2019-0608
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0608
Common Vulnerability Exposure (CVE) ID: CVE-2019-1060
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1060
Common Vulnerability Exposure (CVE) ID: CVE-2019-11091
Common Vulnerability Exposure (CVE) ID: CVE-2019-1166
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1166
Common Vulnerability Exposure (CVE) ID: CVE-2019-1192
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1192
Common Vulnerability Exposure (CVE) ID: CVE-2019-1238
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1238
Common Vulnerability Exposure (CVE) ID: CVE-2019-1307
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1307
Common Vulnerability Exposure (CVE) ID: CVE-2019-1308
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1308
Common Vulnerability Exposure (CVE) ID: CVE-2019-1311
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1311
Common Vulnerability Exposure (CVE) ID: CVE-2019-1315
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1315
Common Vulnerability Exposure (CVE) ID: CVE-2019-1316
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1316
Common Vulnerability Exposure (CVE) ID: CVE-2019-1317
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1317
Common Vulnerability Exposure (CVE) ID: CVE-2019-1318
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1318
Common Vulnerability Exposure (CVE) ID: CVE-2019-1319
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1319
Common Vulnerability Exposure (CVE) ID: CVE-2019-1325
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1325
Common Vulnerability Exposure (CVE) ID: CVE-2019-1326
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1326
Common Vulnerability Exposure (CVE) ID: CVE-2019-1333
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333
Common Vulnerability Exposure (CVE) ID: CVE-2019-1334
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1334
Common Vulnerability Exposure (CVE) ID: CVE-2019-1335
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1335
Common Vulnerability Exposure (CVE) ID: CVE-2019-1339
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1339
Common Vulnerability Exposure (CVE) ID: CVE-2019-1341
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1341
Common Vulnerability Exposure (CVE) ID: CVE-2019-1342
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1342
Common Vulnerability Exposure (CVE) ID: CVE-2019-1343
http://packetstormsecurity.com/files/154798/Microsoft-Windows-Kernel-nt-MiOffsetToProtos-NULL-Pointer-Dereference.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1343
Common Vulnerability Exposure (CVE) ID: CVE-2019-1344
http://packetstormsecurity.com/files/154799/Microsoft-Windows-Kernel-CI-CipFixImageType-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1344
Common Vulnerability Exposure (CVE) ID: CVE-2019-1346
http://packetstormsecurity.com/files/154801/Microsoft-Windows-Kernel-CI-HashKComputeFirstPageHash-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1346
Common Vulnerability Exposure (CVE) ID: CVE-2019-1347
http://packetstormsecurity.com/files/154802/Microsoft-Windows-Kernel-nt-MiRelocateImage-Out-Of-Bounds-Read.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1347
Common Vulnerability Exposure (CVE) ID: CVE-2019-1357
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1357
Common Vulnerability Exposure (CVE) ID: CVE-2019-1358
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1358
Common Vulnerability Exposure (CVE) ID: CVE-2019-1359
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1359
Common Vulnerability Exposure (CVE) ID: CVE-2019-1366
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1366
Common Vulnerability Exposure (CVE) ID: CVE-2019-1367
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1367
Common Vulnerability Exposure (CVE) ID: CVE-2019-1371
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1371
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.