- Total Plugins 68,728
Microsoft Windows Multiple Vulnerabilities (KB4516044)
Windows : Microsoft Bulletins
- ID: 1.3.6.1.4.1.25623.1.0.815457
CVSS Base Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
Summary:
This host is missing a critical security
update according to Microsoft KB4516044
Detection Method:
Checks if a vulnerable version is present
on the target host.
Technical Details:
Multiple flaws exists due to,
- Chakra scripting engine improperly handles objects in memory in
Microsoft Edge.
- An error in Windows Text Service Framework (TSF) when the TSF server process
does not validate the source of input or commands it receives.
- Diagnostics Hub Standard Collector Service improperly impersonates
certain file operations.
- Windows Common Log File System (CLFS) driver improperly handles
objects in memory.
- DirectX improperly handles objects in memory.
- Windows Transaction Manager improperly handles objects in memory.
- Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
- An elevation of privilege exists in hdAudio.
For more information about the vulnerabilities refer Reference links.
Impact:
Successful exploitation will allow an attacker
to gain elevated privileges, execute code with elevated permissions, obtain
information to further compromise the user's system and cause a target
system to stop responding.
Affected Versions:
Microsoft Windows 10 Version 1607 x32/x64
Microsoft Windows Server 2016
Recommendations:
The vendor has released updates. Please see
the references for more information.
Solution Type:
Vendor Patch
Detection Type:
Executable
CVE-2018-12127
CVE-2018-12130
CVE-2019-0787
CVE-2019-0788
CVE-2019-0928
CVE-2019-11091
CVE-2019-1138
CVE-2019-1142
CVE-2019-1208
CVE-2019-1214
CVE-2019-1215
CVE-2019-1216
CVE-2019-1219
CVE-2019-1220
CVE-2019-1221
CVE-2019-1232
CVE-2019-1235
CVE-2019-1236
CVE-2019-1237
CVE-2019-1240
CVE-2019-1241
CVE-2019-1242
CVE-2019-1243
CVE-2019-1244
CVE-2019-1245
CVE-2019-1246
CVE-2019-1247
CVE-2019-1248
CVE-2019-1249
CVE-2019-1250
CVE-2019-1252
CVE-2019-1254
CVE-2019-1256
CVE-2019-1267
CVE-2019-1268
CVE-2019-1269
CVE-2019-1270
CVE-2019-1271
CVE-2019-1272
CVE-2019-1274
CVE-2019-1278
CVE-2019-1280
CVE-2019-1282
CVE-2019-1285
CVE-2019-1286
CVE-2019-1287
CVE-2019-1289
CVE-2019-1290
CVE-2019-1291
CVE-2019-1292
CVE-2019-1293
CVE-2019-1298
CVE-2019-1300
You never have to pay for a vulnerability scanning and management software again.
Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.