Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Hypervisor Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Windows incorrectly allows certain kernel-mode pages to be marked as Read, Write, Execute (RWX) even with Hypervisor Code Integrity (HVCI) enabled.   To exploit this vulnerability, an attacker could run a specially crafted application...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4338 Views

RISK: Medium Risk

Medium Risk

Microsoft .NET Framework TLS/SSL Information Disclosure Vulnerability

An information disclosure vulnerability exists in the TLS/SSL protocol, implemented in the encryption component of Microsoft .NET Framework. An attacker who successfully exploited this vulnerability could decrypt encrypted SSL/TLS traffic.   To exploit the vulnerability, an attacker would first have to inject...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4160 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities

Multiple elevation of privilege vulnerabilities exist in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4012 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows RPC Elevation of Privilege Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows handles specially crafted Remote Procedure Call (RPC) requests. The remote code execution can occur when the RPC Network Data Representation (NDR) Engine improperly frees memory. An authenticated attacker who successfully exploited this...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4298 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links. An attacker who successfully exploited this vulnerability could potentially access privileged registry keys and thereby elevate permissions. An attacker could then install programs; view, ...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 3898 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Media Center Remote Code Execution Vulnerability

A vulnerability exists in Windows Media Center that could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploited this vulnerability could take control of an affected system. Customers whose...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 3943 Views

RISK: High Risk

High Risk

Microsoft Windows IIS Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft Windows fails to properly validate input before loading certain libraries. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4033 Views

RISK: High Risk

High Risk

Microsoft Windows Shell Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Windows Shell improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take control of the affected system. An attacker could then install programs; view, change, or delete data; or...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4075 Views

RISK: High Risk

High Risk

Microsoft Windows Journal Memory Corruption Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 4098 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Graphics Component Multiple Vulnerabilities

Information disclosure vulnerabilities exist when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerabilities could obtain information to further compromise the user’s system.   There are multiple ways an attacker could exploit the vulnerabilities, such as by...
Last Update Date: 12 May 2016 Release Date: 11 May 2016 3995 Views