Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20171222-01-WINDOWS
HistoryDec 22, 2017 - 12:00 a.m.

Security Advisory - Remote Code Execution Vulnerability in Microsoft Windows Print Spooler Service

2017-12-2200:00:00
Huawei Technologies
www.huawei.com
22

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.971

Percentile

99.8%

Microsoft released a security bulletin MS10-061 to publicly disclose a remote code execution vulnerability in the Print Spooler service. The vulnerability could allow remote code execution if an attacker sends a specially crafted print request to a vulnerable system. (Vulnerability ID: HWPSIRT-2017-05163)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2010-2729.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171222-01-windows-en

Affected configurations

Vulners
Node
huaweianyofficeMatchv200r002c10
OR
huaweianyofficeMatchv200r002c20
OR
huaweianyofficeMatchv200r005c02
OR
huaweismc2.0Matchv100r003c10
OR
huaweismc2.0Matchv100r005c00
OR
huaweismc2.0Matchv500r002c00
OR
huaweisecospace_antiddos8000Matchv100r001c00
OR
huaweisecospace_antiddos8000Matchv500r001c00
OR
huaweisecospace_antiddos8000Matchv500r001c20
OR
huaweisecospace_antiddos8000Matchv500r001c60
OR
huaweisecospace_antiddos8000Matchv500r001c80
OR
huaweisecospace_antiddos8160Matchv100r001c00spc300

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.971

Percentile

99.8%