Beschreibung
Multiple serious vulnerabilities have been found in Microsoft Graphics Component. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information and execute arbitrary code.
Below is a complete list of vulnerabilities:
- An incorrect object handling in memory can be exploited remotely to execute arbitrary code in kernel mode;
- An improper disclosure of contents of GDI component can be exploited remotely via a specially designed document or webpage to obtain sensitive information;
- An incorrect object handling in memory can be exploited remotely to obtain sensitive information and in combination with another vulnerability it can allow arbitrary code execution;
- An incorrect object handling in memory can be exploited remotely via a specially designed document or webpage to obtain sensitive information;
- An incorrect object handling in memory in the Color Management Module (ICM32.dll) can be exploited remotely via a specially designed website to obtain sensitive information and in combination with another vulnerability it can allow arbitrary code execution;
- An incorrect object handling in memory can be exploited remotely by making user vist a specially designed website or document file to execute arbitrary code.
Technical details
To exploit vulnerabilities (1) and (2), a malicious user has to be logged on to the system and execute a specially designed application.
In case of vulnerability (6), for affected Microsoft Office products, an attack vector is the Preview Pane.
Ursprüngliche Informationshinweise
- CVE-2017-0014
- CVE-2017-0060
- CVE-2017-0061
- CVE-2017-0062
- CVE-2017-0063
- CVE-2017-0025
- CVE-2017-0073
- CVE-2017-0108
- CVE-2017-0038
- CVE-2017-0001
- CVE-2017-0005
- CVE-2017-0047
CVE Liste
- CVE-2017-0014 critical
- CVE-2017-0060 critical
- CVE-2017-0061 critical
- CVE-2017-0062 critical
- CVE-2017-0063 critical
- CVE-2017-0025 critical
- CVE-2017-0073 critical
- CVE-2017-0108 critical
- CVE-2017-0038 critical
- CVE-2017-0001 critical
- CVE-2017-0005 critical
- CVE-2017-0047 critical
KB Liste
- 4012217
- 4012215
- 4012216
- 4012606
- 4013198
- 4013429
- 4012212
- 4012214
- 4012213
- 4012583
- 4012497
- 4017018
- 4012584
- 4013075
- 3127945
- 3127958
- 3141535
- 3172539
- 3178653
- 3178656
- 3178688
- 3178693
- 4010299
- 4010300
- 4010301
- 4010303
- 4010304
- 4013867
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!