Description
Multiple vulnerabilities were found in Microsoft Windows. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, gain privileges, bypass security restrictions, cause denial of service.
Below is a complete list of vulnerabilities:
- A remote code execution vulnerability in Microsoft Office/WordPad can be exploited remotely via specially crafted files to execute arbitrary code.
- An information disclosure vulnerability in Win32k can be exploited remotely via specially crafted application to obtain sensitive information.
- An elevation of privilege vulnerability in Win32k can be exploited remotely via specially crafted application to gain privileges.
- A security feature bypass vulnerability in ADFS can be exploited remotely via specially crafted application to bypass security restrictions.
- A denial of service vulnerability in Active Directory can be exploited remotely to cause denial of service.
- An elevation of privilege vulnerability in Windows can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in LDAP can be exploited remotely via specially crafted application to gain privileges.
- An information disclosure vulnerability in Windows Kernel can be exploited remotely via specially crafted application to obtain sensitive information.
- A denial of service vulnerability in Windows IPSec can be exploited remotely to cause denial of service.
- An information disclosure vulnerability in OpenType Font Driver can be exploited remotely via specially crafted fonts to obtain sensitive information.
- An elevation of privilege vulnerability in Windows OLE can be exploited remotely to gain privileges.
- A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
- An information disclosure vulnerability in libjpeg can be exploited remotely via specially crafted application to obtain sensitive information.
Original advisories
- CVE-2017-0058
- CVE-2017-0155
- CVE-2017-0156
- CVE-2017-0159
- CVE-2017-0164
- CVE-2017-0165
- CVE-2017-0166
- CVE-2017-0167
- CVE-2017-0188
- CVE-2017-0189
- CVE-2017-0191
- CVE-2017-0192
- CVE-2017-0211
- CVE-2017-0158
- CVE-2013-6629
Exploitation
This vulnerability can be exploited by the following malware:
https://threats.kaspersky.com/en/threat/Exploit.MSOffice.CVE-2017-0199/
https://threats.kaspersky.com/en/threat/Exploit.MSOffice.Oleink/
https://threats.kaspersky.com/en/threat/Trojan.Win32.FormBook/
https://threats.kaspersky.com/en/threat/Trojan-PSW.Win32.Azorult/
The following public exploits exists for this vulnerability:
https://www.exploit-db.com/exploits/42995
https://www.exploit-db.com/exploits/41894
https://www.exploit-db.com/exploits/41934
https://threats.kaspersky.com/en/threat/Exploit.MSOffice.CVE-2017-0199/
https://threats.kaspersky.com/en/threat/Exploit.MSOffice.Oleink/
https://threats.kaspersky.com/en/threat/Trojan-PSW.Win32.Azorult/
https://threats.kaspersky.com/en/threat/Trojan.Win32.FormBook/
https://www.exploit-db.com/exploits/41879
https://www.exploit-db.com/exploits/41901
https://www.exploit-db.com/exploits/41880
https://www.exploit-db.com/exploits/41902
Related products
- Microsoft-Windows
- Microsoft-Windows-Server
- Microsoft-Windows-Vista-4
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Windows-RT
- Microsoft-Windows-10
CVE list
- CVE-2017-0199 critical
- CVE-2017-0058 warning
- CVE-2017-0155 high
- CVE-2017-0156 high
- CVE-2017-0159 warning
- CVE-2017-0164 warning
- CVE-2017-0165 high
- CVE-2017-0166 critical
- CVE-2017-0167 warning
- CVE-2017-0188 warning
- CVE-2017-0189 high
- CVE-2017-0191 warning
- CVE-2017-0192 warning
- CVE-2017-0211 warning
- CVE-2017-0158 critical
- CVE-2013-6629 critical
KB list
- 4015550
- 4015221
- 4015551
- 4015219
- 4015548
- 4014793
- 4015217
- 4015583
- 4015068
- 4015195
- 4015380
- 4015547
- 4015067
- 4014652
- 4014794
- 4015383
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com