Rewterz
Rewterz Threat Advisory – Microsoft .NET Framework Multiple Vulnerabilities
December 17, 2018
Rewterz
Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 17, 2018

Rewterz Threat Advisory – Microsoft Windows Server 2019 Multiple Vulnerabilities

SEVERITY: HIGH

 

 

CATEGORY: VULNERABILITY

 

 

PUBLISH DATE: DECEMBER 17, 2018

 

 

ANALYSIS SUMMARY

 

Total 14 vulnerabilities have been detected in Microsoft Windows Server 2019.

These include the following errors:

 

  • An error related to Windows kernel when handling objects in memory can be exploited to cause information disclosure.
  • Remote Procedure Call Provider has a runtime error when initializing objects in memory, exploiting which, attackers can access certain confidential data.
  • Multiple errors related to the Windows GDI component when handling objects in memory can be exploited to disclose memory contents.
  • An error related to Windows kernel when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges. This flaw is being exploited in limited targeted attacks.
  • An error related to the Connected User Experiences and Telemetry service can be exploited to disrupt security feature functionality, bypassing some restrictions.
  • Using a specially crafted request, an attacker can execute arbitrary code with system privileges by exploiting an error related to DNS Server that will cause a heap-based overflow.
  • An error related to text-to-speech when handling objects in memory can be exploited to execute arbitrary code.
  • An error related to the Win32k component when handling objects in memory can be exploited to disclose uninitialized kernel memory and subsequently bypass KASLR.
  • An error related to DirectX when handling objects in memory can be exploited to disclose certain information.
  • An error related to the Win32k component when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges.
  • An error related to the kernel mode driver when handling objects in memory can be exploited to execute arbitrary code with kernel mode privileges.
  • An error when handling objects in memory can be exploited to cause the system to stop responding.

 

 

IMPACT

 

System access, Denial of Service, Privilege escalation, Exposure of sensitive information

 

 

AFFECTED PRODUCTS

 

 

Microsoft Windows Server 2019

 

 

REMEDIATION

 

 

Apply update.

Windows Server 2019 (KB4471332): Windows Server 2019 (Server Core installation) (KB4471332): https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332