Table of Contents
Learn about just one page Access, Windows PC can also be hacked, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Just One Page Access, Windows PC Can Also Be Hacked Overview
Microsoft has released a patch Patch Tuesday fixes many critical vulnerabilities on Windows and other products, five of which allow attackers to hack computers when users only need to access a website.
These five critical vulnerabilities are included in the Windows Graphics Component, due to improper handling of embedded fonts of Windows font libraries and affecting all Windows versions, including Windows 10 / 8. 1 / RT 8. 1 / 7, Windows Server 2008/2012/2016.
Users just need to open the file or access the website using poisoned font, when opening on the browser will make the hacker take control of the machine. All five of these vulnerabilities were discovered and reported by researcher Hossein Lotfi at Flexera Software.
- CVE-2018-1010
- CVE-2018-1012
- CVE-2018-1013
- CVE-2018-1015
- CVE-2018-1016
Windows Microsoft Graphics is also affected by a denial of service attack, causing the victim's computer to stop responding. This error is caused by the way Windows handles objects in memory.
In addition, Microsoft also announced details of the critical RCE vulnerability (CVE-201801994) in Windows VBScript Engine and affects all versions of Windows.
Many serious holes were patched in the third update
'In the Web-based attack scenario, the attacker hosts a website specifically designed to exploit the vulnerability through Internet Explorer and then make the site accessible to users,' Microsoft explained. 'An attacker can embed the embedded ActiveX Control as' safe 'in an Microsoft Office application or file with an IE rendering engine.'
In addition, Microsoft also patched many vulnerabilities in remote code execution in Microsoft Office and Excel, patched six bugs in Adobe Flash Player, three of which were considered serious.
The remaining errors belong to Windows, Microsoft Office, Internet Explorer, Microsoft Edge, ChakraCore, Malware Protection Engine, Microsoft Visual Studio, and Microsoft Azure IoT SDK, along with errors on Adobe Flash Player
Users should update the patch as quickly as possible by going to Settings> Update and Security> Windows Update> Check for Updates.
See more:
- Instructions for installing Windows 10 Spring Creators Update
- How to enable redirection blocking to malicious websites on Google Chrome
- Update Teamviewer now if you don't want to be hacked
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does just One Page Access, Windows PC Can Also Be Hacked matter?
Learn about just one page Access, Windows PC can also be hacked, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.