Rewterz Threat Advisory – Microsoft Multiple Products Multiple Vulnerabilities
December 17, 2018Rewterz Threat Advisory – CVE-2017-3623 – IBM AIX / Virtual I/O Server RPC Arbitrary Code Execution Vulnerability
December 17, 2018Rewterz Threat Advisory – Microsoft Multiple Products Multiple Vulnerabilities
December 17, 2018Rewterz Threat Advisory – CVE-2017-3623 – IBM AIX / Virtual I/O Server RPC Arbitrary Code Execution Vulnerability
December 17, 2018SEVERITY: Medium
CATEGORY: Vulnerability
PUBLISH DATE: December 17, 2018
ANALYSIS SUMMARY:
CVE-2018-8596: When the Windows GDI component improperly discloses the contents of its memory, it causes information disclosure.
CVE-2018-8595: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory.
CVE-2018-8514: When Remote Procedure Call run-time improperly initializes objects in memory, it may disclose sensitive information.
CVE-2018-8641: Windows kernel-mode driver fails to properly handle objects in memory, leading to elevation of privilege.
CVE-2018-8477: Windows kernel improperly handles objects in memory, resulting in information disclosure.
CVE-2018-8611: Windows kernel fails to properly handle objects in memory, leading to privilege escalation.
CVE-2018-8639: Win32k component fails to properly handle objects in memory in Windows, leading to privilege escalation.
CVE-2018-8621: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory.
CVE-2018-8622: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory.
IMPACT: Privilege escalation, Exposure of sensitive information
AFFECTED PRODUCTS:
Microsoft Windows Server 2008
Microsoft Windows 7
REMEDIATION:
Apply update.
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 (KB4471318):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471318
Windows 7 for x64-based Systems Service Pack 1 (KB4471318):
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB4471318):
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4471318):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471318
Windows 7 for 32-bit Systems Service Pack 1 (KB4471318):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471318
Windows Server 2008 for Itanium-Based Systems Service Pack 2 (KB4471319):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471319
Windows Server 2008 for x64-based Systems Service Pack 2 (KB4471319):
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB4471319):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471319
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB4471319):
Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4471319):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471319
Windows Server 2008 for Itanium-Based Systems Service Pack 2 (KB4471325):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471325
Windows Server 2008 for x64-based Systems Service Pack 2 (KB4471325):
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB4471325):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471325
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB4471325):
Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4471325):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471325
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 (KB4471328):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471328
Windows 7 for x64-based Systems Service Pack 1 (KB4471328):
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB4471328):
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4471328):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471328
Windows 7 for 32-bit Systems Service Pack 1 (KB4471328):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471328
If you think you’re a victim of a cyber-attack, immediately send an e-mail to soc@rewterz.com for a quick response.