Lucene search

K
mskbMicrosoftKB4056895
HistoryJan 03, 2018 - 8:00 a.m.

January 8, 2018—KB4056895 (Monthly Rollup)

2018-01-0308:00:00
Microsoft
support.microsoft.com
57

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.079

Percentile

94.4%

January 8, 2018—KB4056895 (Monthly Rollup)

Improvements and fixes

This security update includes improvements and fixes that were a part of update KB4054519 (released December 12, 2017). It addresses the following issues:

  • Security updates to Windows Kernel, Windows Datacenter Networking, Windows Graphics, and Internet Explorer.
    For more information about the resolved security vulnerabilities, see the Security Update Guide.

Known issues in this update

Symptom Workaround
When calling CoInitializeSecurity, the call fails if passing RPC_C_IMP_LEVEL_NONE under certain conditions.When calling CoInitializeSecurity, the call may fail when passing RPC_C_AUTHN_LEVEL_NONE as the authentication level. The error message that’s returned on the failure is: STATUS_BAD_IMPERSONATION_LEVEL. This issue is resolved in KB4057401.
Microsoft has reports of some customers on a small subset of older AMD processors getting into an unbootable state after installing this KB.

To prevent this issue, Microsoft will temporarily pause Windows OS updates to devices with impacted AMD processors at this time.| This issue is resolved in KB4073576.
Because of an issue that affects some versions of antivirus software, this fix applies only to computers on which the antivirus ISV updated the ALLOW REGKEY.| This issue is resolved in KB4093114. You no longer need the following ALLOW REGKEY to detect and be offered this update: HKEY_LOCAL_MACHINE"Subkey="SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat\cadca5fe-87d3-4b96-b7fb-a231484277cc
After installing this update, some systems running both PIC and APIC interrupt controllers may experience system crashes.| This issue is resolved in KB4077561.
Editing some group policies using GPMC or AGPM 4.0 may fail with error “The data present in the reparse point buffer is invalid. (Exception from HRESULT: 0x80071128)” after installing this update on a domain controller.| This issue is resolved in KB4074594.

How to get this update

This update will be downloaded and installed automatically from Windows Update. To get the standalone package for this update, go to the Microsoft Update Catalog website.File informationFor a list of the files that are provided in this update, download the file information for update 4056895.

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.079

Percentile

94.4%