SB2017031505 - Multiple vulnerabilities in Microsoft Windows
Published: March 14, 2017 Updated: March 17, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-0073)
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application and retrieve information from a targeted system.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
2) Memory corruption (CVE-ID: CVE-2017-0014)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A remote attacker can create a specially crafted Web site containing a malicious content, trick the victim into visiting it and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
3) Information disclosure (CVE-ID: CVE-2017-0060)
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application and retrieve information from a targeted system.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
4) Memory corruption (CVE-ID: CVE-2017-0108)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A remote attacker can create a specially crafted Web site containing a malicious Word content, trick the victim into visiting it and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
5) ASLR bypass (CVE-ID: CVE-2017-0061)
The disclosed vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability is caused by incorrect filtration of input data in Color Management Module (ICM32.dll). A remote attacker can trick the victim to follow a specially crafted website, trigger out-of-bounds read and gain access to parts of system memory.
Successful exploitation of this vulnerability may allow a remote attacker to gain access to potentially sensitive data in memory and bypass ASLR protection.
6) Information disclosure (CVE-ID: CVE-2017-0062)
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application and retrieve information from a targeted system.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
7) Privilege escalation (CVE-ID: CVE-2017-0047)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application, gain elevated privileges and execute arbitrary code on the affected system.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
8) Privilege escalation (CVE-ID: CVE-2017-0025)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application, gain elevated privileges and execute arbitrary code on the affected system.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
9) Privilege escalation (CVE-ID: CVE-2017-0005)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application, gain elevated privileges and execute arbitrary code on the affected system.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
10) Privilege escalation (CVE-ID: CVE-2017-0001)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to improper handling of objects in memory by Windows Graphics Device Interface (GDI). A local attacker can run a specially crafted application, gain elevated privileges and execute arbitrary code on the affected system.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
11) ASLR bypass (CVE-ID: CVE-2017-0063)
The disclosed vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability is caused by incorrect filtration of input data in Color Management Module (ICM32.dll). A remote attacker can trick the victim to follow a specially crafted website, trigger out-of-bounds read and gain access to parts of system memory.
Successful exploitation of this vulnerability may allow a remote attacker to gain access to potentially sensitive data in memory and bypass ASLR protection.
Remediation
Install update from vendor's website.