CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-0173 漏洞信息: Microsoft Windows Security Update June 2017

2017年6月17日 1421点热度 0人点赞 0条评论

漏洞类别:Windows

漏洞等级:

漏洞信息

Microsoft has released Cumulative Security Updates for Windows which addresses the following vulnerabilities:

A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, allowing an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass.
An elevation of privilege vulnerability exists when tdx.sys fails to check the length of a buffer prior to copying memory to the buffer.
A remote code execution exists in Microsoft Windows that could allow remote code execution if the icon of a specially crafted shortcut is displayed.

KB Articles associated with the Update:
3217845
4018106
4019204
4019263
4019264
4021903
4021923
4022008
4022010
4022013
4022714
4022715
4022717
4022718
4022719
4022722
4022724
4022725
4022726
4022727
4022883
4022884
4022887
4024402

漏洞危害

Successful exploitation allows an attacker to execute arbitrary code and take control of an affected system.

解决方案

Customers are advised to refer to Microsoft Security Guidance for more details pertaining to this vulnerability.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Microsoft Security Guidance

0daybank

标签: 暂无
最后更新:2017年6月27日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me