MS17-013: Security Update for Microsoft Graphics Component (4013075)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote Windows host is affected by multiple vulnerabilities.

Description :

The remote Windows host is missing a security update. It is,
therefore, affected by multiple vulnerabilities :

- Multiple elevation of privilege vulnerabilities exist in
the Windows Graphics Device Interface (GDI) component
due to improper handling of objects in memory. A local
attacker can exploit these vulnerabilities, via a
specially crafted application, to execute arbitrary code
in kernel mode. (CVE-2017-0001, CVE-2017-0005,
CVE-2017-0025, CVE-2017-0047)

- Multiple remote code execution vulnerabilities exist in
the Windows Graphics component due to improper handling
of objects in memory. An unauthenticated, remote
attacker can exploit these vulnerabilities, by
convincing a user to visit a specially crafted web page
or open a specially crafted document, to execute
arbitrary code. (CVE-2017-0014, CVE-2017-0108)

- An information disclosure vulnerability exists in the
Windows Graphics Device Interface (GDI) component due to
improper handling of objects in memory. An
unauthenticated, remote attacker can exploit this, by
convincing a user to visit a specially crafted web page
or open a specially crafted document, to disclose the
contents of memory. (CVE-2017-0038)

- Multiple information disclosure vulnerabilities exist in
the Windows Graphics Device Interface (GDI) component
due to improper handling of memory addresses. A local
attacker can exploit these vulnerabilities, via a
specially crafted application, to disclose sensitive
information. (CVE-2017-0060, CVE-2017-0062,
CVE-2017-0073)

- Multiple information disclosure vulnerabilities exist in
the Color Management Module (ICM32.dll) due to improper
handling of objects in memory. An unauthenticated,
remote attacker can exploit this, by convincing a user
to visit a specially crafted web page, to disclose
sensitive information and bypass usermode Address Space
Layout Randomization (ASLR). (CVE-2017-0061,
CVE-2017-0063)

See also :

https://technet.microsoft.com/library/security/ms17-013

Solution :

Microsoft has released a set of patches for Windows XP, 2003, Vista,
2008, 7, 2008 R2, 2012, 8.1, RT 8.1, 2012 R2, 10, and 2016.
Additionally, Microsoft has released a set of patches for Office 2007,
Office 2010, Word Viewer, Skype for Business 2016, Lync 2010, Lync
2010 Attendee, Lync 2013, Lync Basic 2013, Live Meeting 2007 Console,
and Silverlight 5.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.3
(CVSS2#E:POC/RL:OF/RC:ND)
Public Exploit Available : true

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now