This script is Copyright (C) 2016-2017 Tenable Network Security, Inc.
The remote Windows host is affected by multiple vulnerabilities.
The remote Windows host is missing a security update. It is,
therefore, affected by multiple vulnerabilities :
- Multiple information disclosure vulnerabilities exist
due to improper parsing of .pdf files. An
unauthenticated, remote attacker can exploit these
vulnerabilities by convincing a user to open a specially
crafted .pdf file, resulting in the disclosure of
sensitive information in the context of the current
user. (CVE-2016-3201, CVE-2016-3215)
- A remote code execution vulnerability exists due to
improper parsing of .pdf files. An unauthenticated,
remote attacker can exploit this vulnerability by
convincing a user to open a specially crafted .pdf file,
resulting in the execution of arbitrary code in the
context of the current user. (CVE-2016-3203)
See also :
Microsoft has released a set of patches for Windows 2012, 8.1, 2012
R2, and 10.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false