CVE-2017-8597 | Microsoft Edge Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when Microsoft Edge does not properly handle objects in memory. Attackers who successfuly exploit the vulnerability can obtain information to further compromise the user's system. The security update addresses the vulnerability by changing how Microsoft Edge handles objects in memory.
CVE-2017-8629 | Microsoft SharePoint XSS Vulnerability
Risk Rating: Important
This security update resolves an elevation of privilege vulnerability when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. This update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.
CVE-2017-8630 | Microsoft Office Memory Corruption Vulnerability
Risk Rating: Important
This security update resolves a remote code execution vulnerability in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The security update addresses the vulnerability by correcting how Microsoft Office handles files in memory.
CVE-2017-8631 | Microsoft Office Memory Corruption Vulnerability
Risk Rating: Important
This security update resolves a vulnerability the way JavaScript engines render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The security update addresses the vulnerability by modifying how Microsoft browser JavaScript scripting engines handle objects in memory.
CVE-2017-8632 | Microsoft Office Memory Corruption Vulnerability
Risk Rating: Important
This security update resolves a remote code execution vulnerability in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. This security update addresses the vulnerability by correcting how Microsoft Office handles files in memory.
CVE-2017-8675 | Win32k Elevation of Privilege Vulnerability
Risk Rating: Important
This security update resolves an elevation of privilege vulnerability in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. This update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
CVE-2017-8676| Windows GDI Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. The security update addresses the vulnerability by correcting how GDI handles memory addresses.
CVE-2017-8677| Win32k Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when the Windows GDI component improperly discloses kernel memory addresses. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. This security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
CVE-2017-8678 | Win32k Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
CVE-2017-8679 | Windows Kernel Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. This update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
CVE-2017-8680 |Win32k Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability exists when the Windows GDI component improperly discloses kernel memory addresses. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. This security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
CVE-2017-8681 | Win32k Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when the Windows GDI component improperly discloses kernel memory addresses. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. This security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
CVE-2017-8682 | Win32k Graphics Remote Code Execution Vulnerability
Risk Rating: Important
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited this vulnerability could take control of the affected system. This security update addresses the vulnerabilities by correcting how the Windows font library handles embedded fonts.
CVE-2017-8683 | Win32k Graphics Information Disclosure Vulnerability
Risk Rating: Important
This security update resolves an information disclosure vulnerability when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.