Multiple vulnerabilities have been reported in Microsoft Windows Server 2012, Microsoft Windows RT 8.1, and Microsoft Windows 8.1. Updates are available that fix these vulnerabilities.
PUBLISH DATE: 11-14-2018
Multiple vulnerabilities have been reported in Microsoft Windows Server 2012, Microsoft Windows RT 8.1, and Microsoft Windows 8.1, which can be exploited by malicious, local users to disclose sensitive information, bypass certain security restrictions, and gain escalated privileges. Updates are available for fixing these vulnerabilities.
An error related to DirectX while handling objects in memory can be exploited to disclose certain data. The successful exploitation of these vulnerabilities may cause significant inconveniences including exposure of sensitive information, script insertion attacks and Security Bypass. Local users with malicious intent may also gain elevated privileges.
A number of CVE references are associated with the updates, whose descriptions are not available at the time of creation of this advisory.
Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows 8.1
Update the following versions as suggested:
Apply update (please see the vendor’s service database for details).
Note: Security updates for Windows RT 8.1 are available via e.g. Windows Update or Windows Update Catalog only.
It is recommended to update the products you’re using, if any, as soon as possible.
If you think you’re the victim of a cyber-attack, immediately send an email to firstname.lastname@example.org.