CVE-2017-0052

CVE: CVE-2017-0052
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: office_compatibility_pack
Versions: *,
excel_viewer
Versions: *,
sharepoint_server
Versions: 2007,
excel
Versions: 2007,
Description Language: en
Description: Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka “Microsoft Office Memory Corruption Vulnerability.” This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, and CVE-2017-0053.
References:
http://www.securityfocus.com/bid/96741
http://www.securitytracker.com/id/1038010
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0052

CVE-2017-0051

CVE: CVE-2017-0051
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607,
windows_server_2016
Versions: *,
Description Language: en
Description: Microsoft Windows 10 1607 and Windows Server 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka “Microsoft Hyper-V Network Switch Denial of Service Vulnerability.” This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, CVE-2017-0098, and CVE-2017-0099.
References:
http://www.securityfocus.com/bid/96026
http://www.securitytracker.com/id/1037999
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0051

CVE-2017-0050

CVE: CVE-2017-0050
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607, 1511, -,
windows_server_2012
Versions: r2, -,
windows_vista
Versions: *,
windows_server_2008
Versions: r2, *,
windows_8
Versions: *,
windows_7
Versions: *,
windows_server_2016
Versions: *,
windows_rt_8.1
Versions: *,
Description Language: en
Description: The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka “Windows Kernel Elevation of Privilege Vulnerability.”
References:
http://www.securityfocus.com/bid/96025
http://www.securitytracker.com/id/1038013
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0050

CVE-2017-0049

CVE: CVE-2017-0049
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: internet_explorer
Versions: 11,
Description Language: en
Description: The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka “Scripting Engine Information Disclosure Vulnerability.” This vulnerability is different from those described in CVE-2017-0018, and CVE-2017-0037.
References:
http://www.securityfocus.com/bid/96095
http://www.securitytracker.com/id/1038008
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0049

CVE-2017-0047

CVE: CVE-2017-0047
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607, 1511, -,
windows_server_2012
Versions: r2, -,
windows_vista
Versions: *,
windows_8.1
Versions: *,
windows_server_2008
Versions: r2, *,
windows_rt_8.1
Versions: *,
windows_7
Versions: *,
Description Language: en
Description: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka “Windows GDI Elevation of Privilege Vulnerability.” This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005 and CVE-2017-0025.
References:
http://www.securityfocus.com/bid/96034
http://www.securitytracker.com/id/1038002
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0047

CVE-2017-0045

CVE: CVE-2017-0045
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_vista
Versions: *,
windows_server_2008
Versions: r2, *,
windows_7
Versions: *,
Description Language: en
Description: Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka “Windows DVD Maker Cross-Site Request Forgery Vulnerability.”
References:
http://hyp3rlinx.altervista.org/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSURE.txt
http://www.securityfocus.com/bid/96103
http://www.securitytracker.com/id/1038015
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0045
https://www.exploit-db.com/exploits/41619/

CVE-2017-0043

CVE: CVE-2017-0043
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607,
windows_server_2012
Versions: r2, -,
windows_server_2008
Versions: r2, *,
windows_server_2016
Versions: *,
Description Language: en
Description: Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka “Microsoft Active Directory Federation Services Information Disclosure Vulnerability.”
References:
http://www.securityfocus.com/bid/96628
http://www.securitytracker.com/id/1038018
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0043

CVE-2017-0042

CVE: CVE-2017-0042
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607, 1511, -,
windows_server_2012
Versions: r2,
windows_vista
Versions: *,
windows_8.1
Versions: *,
windows_server_2008
Versions: r2, *,
windows_server_2016
Versions: *,
windows_rt_8.1
Versions: *,
windows_7
Versions: *,
Description Language: en
Description: Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka “Windows Media Player Information Disclosure Vulnerability.”
References:
http://pastebin.com/raw/Eztknq4s
http://www.securityfocus.com/bid/96098
http://www.securitytracker.com/id/1038016
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0042

CVE-2017-0040

CVE: CVE-2017-0040
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: internet_explorer
Versions: 9, 11, 10,
Description Language: en
Description: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka “Scripting Engine Memory Corruption Vulnerability.” This vulnerability is different from that described in CVE-2017-0130.
References:
http://www.security-assessment.com/files/documents/advisory/reversesegment.pdf
http://www.securityfocus.com/bid/96094
http://www.securitytracker.com/id/1038008
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0040

CVE-2017-0039

CVE: CVE-2017-0039
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_vista
Versions: *,
windows_server_2008
Versions: *,
Description Language: en
Description: Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle dynamic link library (DLL) loading, which allows local users to gain privileges via a crafted application, aka “Library Loading Input Validation Remote Code Execution Vulnerability.”
References:
http://www.securityfocus.com/bid/96024
http://www.securitytracker.com/id/1038001
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0039

CVE-2017-0035

CVE: CVE-2017-0035
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: edge
Versions: -,
Description Language: en
Description: A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.
References:
http://www.securityfocus.com/bid/96082
http://www.securitytracker.com/id/1038006
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0035

CVE-2017-0034

CVE: CVE-2017-0034
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: edge
Versions: *,
Description Language: en
Description: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
References:
http://www.securityfocus.com/bid/96786
http://www.securitytracker.com/id/1038006
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0034

CVE-2017-0033

CVE: CVE-2017-0033
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: internet_explorer
Versions: 11,
edge
Versions: *,
Description Language: en
Description: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka “Microsoft Browser Spoofing Vulnerability.” This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.
References:
http://www.securityfocus.com/bid/96087
http://www.securitytracker.com/id/1038006
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0033

CVE-2017-0032

CVE: CVE-2017-0032
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: edge
Versions: -,
Description Language: en
Description: A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.
References:
http://www.securityfocus.com/bid/96080
http://www.securitytracker.com/id/1038006
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0032

CVE-2017-0031

CVE: CVE-2017-0031
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: office_compatibility_pack
Versions: *,
word
Versions: 2010, 2007,
office
Versions: 2010,
Description Language: en
Description: Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka “Microsoft Office Memory Corruption Vulnerability.” This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0052, and CVE-2017-0053.
References:
http://www.securityfocus.com/bid/96052
http://www.securitytracker.com/id/1038010
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0031

CVE-2017-0030

CVE: CVE-2017-0030
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: sharepoint_server
Versions: 2010,
office_compatibility_pack
Versions: *,
word
Versions: 2010, 2007,
office
Versions: 2010,
office_web_apps
Versions: 2010,
Description Language: en
Description: Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka “Microsoft Office Memory Corruption Vulnerability.” This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.
References:
http://www.securityfocus.com/bid/96051
http://www.securitytracker.com/id/1038010
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0030

CVE-2017-0029

CVE: CVE-2017-0029
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: word
Versions: 2010, 2013, 2016,
office
Versions: 2010,
Description Language: en
Description: Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka “Microsoft Office Denial of Service Vulnerability.”
References:
http://www.securityfocus.com/bid/96045
http://www.securitytracker.com/id/1038010
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0029

CVE-2017-0027

CVE: CVE-2017-0027
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: office_compatibility_pack
Versions: *,
sharepoint_server
Versions: 2013,
excel
Versions: 2016, 2007, 2010, 2013,
Description Language: en
Description: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka “Microsoft Office Information Disclosure Vulnerability.”
References:
http://www.securityfocus.com/bid/96043
http://www.securitytracker.com/id/1038010
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0027

CVE-2017-0026

CVE: CVE-2017-0026
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607, 1511, -,
windows_server_2016
Versions: *,
Description Language: en
Description: The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka “Win32k Elevation of Privilege Vulnerability.” This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.
References:
http://www.securityfocus.com/bid/96032
http://www.securitytracker.com/id/1038017
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0026

CVE-2017-0025

CVE: CVE-2017-0025
Published: 2017-03-17T00:59Z
Vendor: microsoft
Products: windows_10
Versions: 1607, 1511, -,
windows_server_2012
Versions: r2, -,
windows_vista
Versions: *,
windows_8.1
Versions: *,
windows_server_2008
Versions: r2, *,
windows_server_2016
Versions: *,
windows_rt_8.1
Versions: *,
windows_7
Versions: *,
Description Language: en
Description: The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka “Win32k Elevation of Privilege Vulnerability.” This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005, and CVE-2017-0047.
References:
http://www.securityfocus.com/bid/96626
http://www.securitytracker.com/id/1038002
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0025