Описание
Multiple serious vulnerabilities were found in Microsoft Windows. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, cause denial of service.
Below is a complete list of vulnerabilities:
- Multiple vulnerabilities in Windows kernel can be exploited locally via a specially crafted application to gain privileges or obtain sensitive information;
- Multiple security bypass vulnerabilities in Device Guard can be exploited locally to bypass security restrictions;
- Improper handling of objects in memory in Microsoft WordPad can be exploited locally via a specially designed document to bypass security restrictions;
- Improper handling of objects in memory in Microsoft Windows can be exploited locally via a specially designed application to cause denial of service;
- An incorrect permissions enforcing in Windows Kernel API can be exploited locally via a specially crafted application to gain privileges;
- An incorrect DNS responses handling in DNSAPI.dll can be exploited remotely via a specially designed DNS request to cause demial of service;
- An incorrect Windows Sandbox configuration can be exploited locally via a specially designed application to gain privileges;
- Improper FTP connections handling in Windows can be exploited remotely via a specially designed query to cause denial of service.
Первичный источник обнаружения
- CVE-2018-8282
CVE-2018-8314
CVE-2018-8222
CVE-2018-8307
CVE-2018-8309
CVE-2018-8313
CVE-2018-8304
CVE-2018-8308
CVE-2018-8206
Эксплуатация
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Связанные продукты
- Microsoft-Windows
- Microsoft-Windows-Server-2003-Enterprise-Edition
- Microsoft-Windows-Server-2003-Standard-Edition
- Microsoft-Windows-Server-2003-Web-Edition
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Microsoft-Windows-Server-2003
- Microsoft-Windows-10
Список CVE
- CVE-2018-8282 high
- CVE-2018-8314 warning
- CVE-2018-8222 warning
- CVE-2018-8307 high
- CVE-2018-8309 warning
- CVE-2018-8313 high
- CVE-2018-8304 high
- CVE-2018-8308 critical
- CVE-2018-8206 critical
Список KB
- 4338824
- 4338830
- 4338820
- 4338815
- 4338825
- 4338814
- 4338829
- 4338819
- 4338826
- 4345421
- 4345419
- 4338816
- 4345455
- 4338831
- 4345420
- 4345424
- 4345425
- 4345418
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!