Rewterz Threat Advisory – Microsoft .NET Framework Multiple Vulnerabilities
December 17, 2018Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 17, 2018Rewterz Threat Advisory – Microsoft .NET Framework Multiple Vulnerabilities
December 17, 2018Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 17, 2018SEVERITY: HIGH
CATEGORY: VULNERABILITY
PUBLISH DATE: DECEMBER 17, 2018
ANALYSIS SUMMARY
Total 14 vulnerabilities have been detected in Microsoft Windows Server 2019.
These include the following errors:
- An error related to Windows kernel when handling objects in memory can be exploited to cause information disclosure.
- Remote Procedure Call Provider has a runtime error when initializing objects in memory, exploiting which, attackers can access certain confidential data.
- Multiple errors related to the Windows GDI component when handling objects in memory can be exploited to disclose memory contents.
- An error related to Windows kernel when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges. This flaw is being exploited in limited targeted attacks.
- An error related to the Connected User Experiences and Telemetry service can be exploited to disrupt security feature functionality, bypassing some restrictions.
- Using a specially crafted request, an attacker can execute arbitrary code with system privileges by exploiting an error related to DNS Server that will cause a heap-based overflow.
- An error related to text-to-speech when handling objects in memory can be exploited to execute arbitrary code.
- An error related to the Win32k component when handling objects in memory can be exploited to disclose uninitialized kernel memory and subsequently bypass KASLR.
- An error related to DirectX when handling objects in memory can be exploited to disclose certain information.
- An error related to the Win32k component when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges.
- An error related to the kernel mode driver when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges.
- An error when handling objects in memory can be exploited to cause the system to stop responding.
IMPACT
System access, Denial of Service, Privilege escalation, Exposure of sensitive information
AFFECTED PRODUCTS
Microsoft Windows Server 2019
REMEDIATION
Apply update.
Windows Server 2019 (KB4471332): Windows Server 2019 (Server Core installation) (KB4471332): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332