Summary
This host is missing an critical security
update according to Microsoft Bulletin MS14-057.
Impact
Successful exploitation will allow
attackers to bypass certain security restrictions and compromise a vulnerable system.
Impact Level: System/Application
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the link, https://technet.microsoft.com/library/security/MS14-057
Insight
Multiple flaws are due to,
- An unspecified error related to .NET ClickOnce.
- An unspecified error when handling internationalized resource identifiers.
- An unspecified error.
Affected
Microsoft .NET Framework 2.0, 3.5,
3.5.1, 4.0, 4.5, 4.5.1 and 4.5.2
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-4073, CVE-2014-4121, CVE-2014-4122 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Internet Explorer Data Stream Handling Remote Code Execution Vulnerability (947864)
- Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
- Cumulative Security Update for Internet Explorer (937143)
- Microsoft DirectShow Remote Code Execution Vulnerability (977935)
- Buffer Overrun in the ListBox and in the ComboBox (824141)