SB2018031320 - Multiple vulnerabilities in Microsoft Windows Kernel
Published: March 13, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-0904)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
2) Information disclosure (CVE-ID: CVE-2018-0811)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it initializes objects in memory. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and perform further attacks.
3) Information disclosure (CVE-ID: CVE-2018-0894)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
4) Information disclosure (CVE-ID: CVE-2018-0895)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
5) Information disclosure (CVE-ID: CVE-2018-0896)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
6) Information disclosure (CVE-ID: CVE-2018-0897)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
7) Information disclosure (CVE-ID: CVE-2018-0898)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
8) Information disclosure (CVE-ID: CVE-2018-0899)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
9) Information disclosure (CVE-ID: CVE-2018-0900)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
10) Information disclosure (CVE-ID: CVE-2018-0901)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it handles memory addresses. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and bypass a Kernel Address Space Layout Randomization (ASLR).
11) Information disclosure (CVE-ID: CVE-2018-0926)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it initializes objects in memory. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and perform further attacks.
12) Information disclosure (CVE-ID: CVE-2018-0813)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it initializes objects in memory. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and perform further attacks
13) Information disclosure (CVE-ID: CVE-2018-0814)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in the Windows kernel when it initializes objects in memory. A remote attacker can run a specially crafted application to gain access to potentially sensitive information and perform further attacks
14) Privilege escalation (CVE-ID: CVE-2018-0977)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to improper handling of objects in memory by the Windows kernel-mode driver. A local attacker can run a specially crafted application, trigger memory corruption and run arbitrary code in kernel mode.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0904
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0811
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0894
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0895
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0896
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0897
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0898
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0899
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0900
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0901
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0926
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0813
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0814
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0977