Summary
This host is missing an critical security
update according to Microsoft Bulletin MS14-057.
Impact
Successful exploitation will allow
attackers to bypass certain security restrictions and compromise a vulnerable system.
Impact Level: System/Application
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the link, https://technet.microsoft.com/library/security/MS14-057
Insight
Multiple flaws are due to,
- An unspecified error related to .NET ClickOnce.
- An unspecified error when handling internationalized resource identifiers.
- An unspecified error.
Affected
Microsoft .NET Framework 2.0, 3.5,
3.5.1, 4.0, 4.5, 4.5.1 and 4.5.2
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-4073, CVE-2014-4121, CVE-2014-4122 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft GDI+ Remote Code Execution Vulnerability (2489979)
- Microsoft Excel Remote Code Execution Vulnerability (956416)
- Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
- Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
- Cumulative Security Update for Internet Explorer (931768)