Описание
Windows Kernel Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An unauthenticated attacker could host specially crafted Xpress LZ-compressed content on an SMB share and convince a user on an affected system to browse to the share. Successful exploitation could allow the attacker to execute code on the affected system.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Windows Server 2012 | ||
| Windows Server 2012 (Server Core installation) | ||
| Windows Server 2012 R2 | ||
| Windows Server 2012 R2 (Server Core installation) | ||
| Windows Server 2016 | ||
| Windows 10 Version 1607 for 32-bit Systems | ||
| Windows 10 Version 1607 for x64-based Systems | ||
| Windows Server 2016 (Server Core installation) | ||
| Windows 10 Version 1809 for 32-bit Systems | ||
| Windows 10 Version 1809 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.8 High
CVSS3
Связанные уязвимости
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.
EPSS
8.8 High
CVSS3