Description: | Summary: This host is missing a critical security update according to Microsoft KB4525235
Vulnerability Insight: Multiple flaws exist due to:
- Windows improperly handles objects in memory.
- Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system.
- Windows kernel improperly handles objects in memory.
- ActiveX Installer service may allow access to files without proper authentication.
- Windows Certificate Dialog does not properly enforce user privileges.
- VBScript engine improperly handles objects in memory.
- The Win32k component fails to properly handle objects in memory.
Please see the references for more information about the vulnerabilities.
Vulnerability Impact: Successful exploitation will allow an attacker to execute arbitrary code on a victim system, cause a target system to stop responding, obtain information to further compromise the user's system and gain elevated privileges.
Affected Software/OS: - Microsoft Windows 7 for 32-bit/x64 Systems Service Pack 1
- Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|