MS16-130: Security Update for Microsoft Windows (3199172)
High Nessus Plugin ID 94631
SynopsisThe remote host is affected by multiple vulnerabilities.
DescriptionThe remote Windows host is missing a security update or security rollup. It is, therefore, affected by the following vulnerabilities :
- A remote code execution vulnerability exists in the Windows image file handling functionality due to improper handling of image files. An unauthenticated, remote attacker can exploit this vulnerability by convincing a user to open a specially crafted image file from a web page or email message, resulting in the execution of arbitrary code in the context of the current user. (CVE-2016-7212)
- An elevation of privilege vulnerability exists in Windows Input Method Editor (IME) due to improper loading of DLL files. A local attacker can exploit this, via a specially crafted application, to elevate privileges. (CVE-2016-7221)
- An elevation of privilege vulnerability exists in Windows Task Scheduler due to improper handling of UNC paths. An authenticated, remote attacker can exploit this vulnerability by scheduling a new task with a specially crafted UNC path, resulting in the execution of arbitrary code with elevated system privileges.
SolutionMicrosoft has released a set of patches for Windows Vista, 2008, 7, 2008 R2, 2012, 8.1, RT 8.1, 2012 R2, 10, and 2016.