How to Buy
This script is Copyright (C) 2017 Tenable Network Security, Inc.
A web application framework running on the remote host is affected by
multiple remote code execution vulnerabilities.
The version of Silverlight 5 installed on the remote Windows host is
missing security update KB4023307. It is, therefore, affected by
multiple vulnerabilities :
- A remote code execution vulnerability exists in
Windows Uniscribe software due to improper handling of
objects in memory. An unauthenticated, remote attacker
can exploit this, by convincing a user to visit a
specially crafted website or to open a specially crafted
document file, to execute arbitrary code in the context
of the current user. (CVE-2017-0283)
- A remote code execution vulnerability exists in the
Windows font library due to improper handling of
embedded fonts. An unauthenticated, remote attacker can
exploit this, by convincing a user to visit a specially
crafted website or open a specially crafted Microsoft
document, to execute arbitrary code in the context of
the current user. (CVE-2017-8527)
See also :
Apply security update KB4023307.
Risk factor :
High / CVSS Base Score : 9.3
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 100767 ()
Bugtraq ID: 9892098933
CVE ID: CVE-2017-0283CVE-2017-8527
Get Nessus Professional to scan unlimited IPs, run compliance checks & more
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.