Microsoft Browser Information Disclosure Vulnerability for Windows Server 2012 - WannaCrypt Ransomware Worm(KB4012217)

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.318%

CVE Information

Patch Details

Patch associated with this vulnerability is supported by ManageEngine.

Patch ID
22150

Patch Description
March, 2017 Security Monthly Quality Rollup for Windows Server 2012 - WannaCrypt Ransomware Worm(KB4012217)

References

http://blog.inspired-sec.com/archive/2017/03/17/COM-Moniker-Privesc.html
http://www.security-assessment.com/files/documents/advisory/comparestring_infoleak.pdf
http://www.security-assessment.com/files/documents/advisory/reversesegment.pdf
http://www.securityfocus.com/bid/96023
http://www.securityfocus.com/bid/96033
http://www.securityfocus.com/bid/96034
http://www.securityfocus.com/bid/96057
http://www.securityfocus.com/bid/96069
http://www.securityfocus.com/bid/96077
http://www.securityfocus.com/bid/96086
http://www.securityfocus.com/bid/96088
http://www.securityfocus.com/bid/96094
http://www.securityfocus.com/bid/96610
http://www.securityfocus.com/bid/96623
http://www.securityfocus.com/bid/96627
http://www.securityfocus.com/bid/96628
http://www.securityfocus.com/bid/96630
http://www.securityfocus.com/bid/96634
http://www.securityfocus.com/bid/96637
http://www.securityfocus.com/bid/96639
http://www.securityfocus.com/bid/96640
http://www.securityfocus.com/bid/96644
http://www.securityfocus.com/bid/96645
http://www.securityfocus.com/bid/96647
http://www.securityfocus.com/bid/96678
http://www.securityfocus.com/bid/96680
http://www.securityfocus.com/bid/96700
http://www.securityfocus.com/bid/96701
http://www.securityfocus.com/bid/96703
http://www.securityfocus.com/bid/96704
http://www.securityfocus.com/bid/96705
http://www.securityfocus.com/bid/96706
http://www.securityfocus.com/bid/96707
http://www.securityfocus.com/bid/96709
http://www.securityfocus.com/bid/96713
http://www.securityfocus.com/bid/96715
http://www.securitytracker.com/id/1037845
http://www.securitytracker.com/id/1037905
http://www.securitytracker.com/id/1037906
http://www.securitytracker.com/id/1037991
http://www.securitytracker.com/id/1037992
http://www.securitytracker.com/id/1037999
http://www.securitytracker.com/id/1038001
http://www.securitytracker.com/id/1038002
http://www.securitytracker.com/id/1038006
http://www.securitytracker.com/id/1038008
http://www.securitytracker.com/id/1038013
http://www.securitytracker.com/id/1038014
http://www.securitytracker.com/id/1038017
http://www.securitytracker.com/id/1038018
https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html
https://0patch.blogspot.com/2017/09/exploit-kit-rendezvous-and-cve-2017-0022.html
https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html
https://blogs.technet.microsoft.com/mmpc/2017/03/27/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005/
https://bugs.chromium.org/p/project-zero/issues/detail?id=1011
https://bugs.chromium.org/p/project-zero/issues/detail?id=1021
https://bugs.chromium.org/p/project-zero/issues/detail?id=992
https://github.com/k0keoyo/CVE-2017-0038-EXP-C-JS
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0001
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0005
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0008
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0009
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0014
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0018
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0022
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0023
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0025
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0037
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0038
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0040
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0043
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0047
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0055
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0056
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0059
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0060
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0062
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0073
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0074
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0075
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0076
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0078
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0081
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0084
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0096
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0097
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0099
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0100
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0102
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0103
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0104
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0109
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0118
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0121
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0130
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0143
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0144
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0145
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0146
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0147
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0148
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0149
https://www.exploit-db.com/exploits/41363/
https://www.exploit-db.com/exploits/41454/
https://www.exploit-db.com/exploits/41607/
https://www.exploit-db.com/exploits/41645/
https://www.exploit-db.com/exploits/41648/
https://www.exploit-db.com/exploits/41655/
https://www.exploit-db.com/exploits/41656/
https://www.exploit-db.com/exploits/41658/
https://www.exploit-db.com/exploits/41661/
https://www.exploit-db.com/exploits/41891/
https://www.exploit-db.com/exploits/41987/
https://www.exploit-db.com/exploits/42030/
https://www.exploit-db.com/exploits/42031/
https://www.exploit-db.com/exploits/42354/
https://www.exploit-db.com/exploits/43125/