Nessus Report

Report generated by Tenable Nessus™

Server 1

Sat, 10 Jan 2026 05:42:13 India Standard Time

TABLE OF CONTENTS
Vulnerabilities by HostExpand All | Collapse All
172.17.100.73
55
146
35
2
1878
Critical
High
Medium
Low
Info
Scan Information
Start time: Sat Jan 10 05:02:46 2026
End time: Sat Jan 10 05:42:12 2026
Host Information
Netbios Name: XHWAKEYESRV
IP: 172.17.100.73
MAC Address: 40:A8:F0:20:84:35 40:A8:F0:20:84:34 40:A8:F0:20:84:36 40:A8:F0:20:84:37
OS: Microsoft Windows Server 2016 Datacenter Build 14393
Vulnerabilities

156860 - Apache Log4j 1.x Multiple Vulnerabilities
-
Synopsis
A logging library running on the remote host has multiple vulnerabilities.
Description
According to its self-reported version number, the installation of Apache Log4j on the remote host is 1.x and is no longer supported. Log4j reached its end of life prior to 2016. Additionally, Log4j 1.x is affected by multiple vulnerabilities, including :

- Log4j includes a SocketServer that accepts serialized log events and deserializes them without verifying whether the objects are allowed or not. This can provide an attack vector that can be exploited. (CVE-2019-17571)

- Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. (CVE-2020-9488)

- JMSSink uses JNDI in an unprotected manner allowing any application using the JMSSink to be vulnerable if it is configured to reference an untrusted site or if the site referenced can be accesseed by the attacker.
(CVE-2022-23302)

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4904
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-17571
CVE CVE-2020-9488
CVE CVE-2022-23302
CVE CVE-2022-23305
CVE CVE-2022-23307
CVE CVE-2023-26464
XREF CEA-ID:CEA-2021-0004
XREF CEA-ID:CEA-2021-0025
XREF IAVA:2021-A-0573
Plugin Information
Published: 2022/01/19, Modified: 2024/06/13
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17

tcp/445/cifs


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17

182252 - Apache Log4j SEoL (<= 1.x)
-
Synopsis
An unsupported version of Apache Log4j is installed on the remote host.
Description
According to its version, Apache Log4j is less than or equal to 1.x. It is, therefore, no longer maintained by its vendor or provider.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Apache Log4j that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2023/09/29, Modified: 2023/11/02
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

tcp/0


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Security End of Life : August 4, 2015
Time since Security End of Life (Est.) : >= 10 years

235034 - Apache Tomcat 9.0.0.M1 < 9.0.104 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.104. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.104_security-9 advisory.

- Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. Users are recommended to upgrade to version 9.0.104, which fixes the issue. (CVE-2025-31651)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.104 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-31651
XREF IAVA:2025-A-0313-S
Plugin Information
Published: 2025/04/30, Modified: 2025/07/15
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.104
213078 - Apache Tomcat 9.0.0.M1 < 9.0.98 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.98. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.98_security-9 advisory.

- Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue. (CVE-2024-50379)

- Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The mitigation for CVE-2024-50379 was incomplete. Users running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation parameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat: - running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true) - running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false) - running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed) Tomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can. (CVE-2024-56337)

- Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue. (CVE-2024-54677)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.98 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.8843
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-50379
CVE CVE-2024-54677
CVE CVE-2024-56337
XREF IAVA:2024-A-0822-S
Plugin Information
Published: 2024/12/17, Modified: 2025/03/13
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.98
232528 - Apache Tomcat 9.0.0.M1 < 9.0.99
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.99. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.99_security-9 advisory.

- Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue. (CVE-2025-24813)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.99 or later.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9418
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24813
XREF IAVA:2025-A-0156
XREF CISA-KNOWN-EXPLOITED:2025/04/22
Plugin Information
Published: 2025/03/10, Modified: 2025/04/09
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.99
117413 - KB4457131: Windows 10 Version 1607 and Windows Server 2016 September 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4457131.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8457)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2018-8424)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2018-0965, CVE-2018-8439)

- A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files. An attacker who successfully exploited the vulnerability could execute arbitrary code.
(CVE-2018-8475)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8440)

- An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser. An attacker who successfully exploited this vulnerability could gain elevated privileges and break out of the Edge AppContainer sandbox. The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running. The security update addresses the vulnerability by modifying how Microsoft Edge handles sandboxing. (CVE-2018-8469)

- An elevation of privilege vulnerability exists in Windows that allows a sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. This vulnerability by itself does not allow arbitrary code execution. However, the vulnerability could allow arbitrary code to run if an attacker uses it in combination with another vulnerability, such as a remote code execution vulnerability or another elevation of privilege vulnerability, that can leverage the elevated privileges when code execution is attempted.
The security update addresses the vulnerability by correcting how Windows parses files. (CVE-2018-8468)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory. (CVE-2018-8442, CVE-2018-8443)

- An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8419)

- An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit this vulnerability by running a specially crafted application. The security update addresses the vulnerability by helping to ensure that the Windows Kernel API properly handles objects in memory.
(CVE-2018-8410)

- An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-8462)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8446)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2018-8420)

- A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. (CVE-2018-8438)

- An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. (CVE-2018-8434)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8332)

- An information disclosure vulnerability exists when the browser scripting engine improperly handle object types.
An attacker who has successfully exploited this vulnerability might be able to read privileged data across trust boundaries. In browsing scenarios, an attacker could convince a user to visit a malicious site and leverage the vulnerability to obtain privileged information from the browser process, such as sensitive data from other opened tabs. An attacker could also inject malicious code into advertising networks used by trusted sites or embed malicious code on a compromised, but trusted, site. The security update addresses the vulnerability by correcting how the browser scripting engine handles object types. (CVE-2018-8315)

- A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2018-8392, CVE-2018-8393)

- A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server. An attacker who exploited this vulnerability could cause the affected system to crash. To attempt to exploit this issue, an attacker would need to send specially crafted SMB requests to the target system. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests. The security update addresses the vulnerability by correcting the manner in which SMB handles specially crafted client requests.
(CVE-2018-8335)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2018-8455)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8447)

- An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could potentially disclose contents of System memory.
(CVE-2018-8271)

- An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8464)

- A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. (CVE-2018-8421)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8367, CVE-2018-8465, CVE-2018-8466, CVE-2018-8467)

- An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system.
(CVE-2018-8452)

- A security feature bypass exists when Device Guard incorrectly validates an untrusted file. An attacker who successfully exploited this vulnerability could make an unsigned file appear to be signed. Because Device Guard relies on the signature to determine the file is non- malicious, Device Guard could then allow a malicious file to execute. In an attack scenario, an attacker could make an untrusted file appear to be a trusted file. The update addresses the vulnerability by correcting how Device Guard handles untrusted files.
(CVE-2018-8449)

- An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows Graphics Component handles objects in memory. (CVE-2018-8433)

- A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high- entropy source. (CVE-2018-8435)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8354)

- A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition. An attacker could use the UXSS vulnerability to access any session belonging to web pages currently opened (or cached) by the browser at the time the attack is triggered. (CVE-2018-8470)

- A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content. An attacker who successfully exploited this vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
(CVE-2018-8425)
See Also
Solution
Apply Cumulative Update KB4457131.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.7987
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2018/09/11, Modified: 2022/03/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4457131

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2485
118916 - KB4467691: Windows 10 Version 1607 and Windows Server 2016 November 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4467691.
It is, therefore, affected by multiple vulnerabilities :

- A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard. (CVE-2018-8417)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8552)

- A remote code execution vulnerability exists when Windows Search handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8450)

- A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files.
An attacker who successfully exploited this vulnerability could execute malicious code on a vulnerable system. (CVE-2018-8256)

- A security feature bypass exists when Windows incorrectly validates kernel driver signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed drivers into the kernel. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed drivers from being loaded by the kernel. The update addresses the vulnerability by correcting how Windows validates kernel driver signatures. (CVE-2018-8549)

- A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code.
(CVE-2018-8415)

- A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system.
(CVE-2018-8476)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8562)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8542, CVE-2018-8543, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588)

- An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2018-8471)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8584)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8544)

- An elevation of privilege exists in Windows COM Aggregate Marshaler. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2018-8550)

- An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
(CVE-2018-8408)

- A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content. An attacker who successfully exploited this vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
(CVE-2018-8564)

- A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected AD FS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the AD FS site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that the open source customization for AD FS properly sanitizes web requests.
(CVE-2018-8547)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2018-8553)

- An information disclosure vulnerability exists when &quot;Kernel Remote Procedure Call Provider&quot; driver improperly initializes objects in memory.
(CVE-2018-8407)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2018-8565)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8485, CVE-2018-8561)
See Also
Solution
Apply Cumulative Update KB4467691.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7286
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 105770
BID 105772
BID 105774
BID 105775
BID 105777
BID 105779
BID 105780
BID 105781
BID 105782
BID 105785
BID 105786
BID 105787
BID 105789
BID 105790
BID 105791
BID 105792
BID 105794
BID 105795
BID 105797
BID 105800
BID 105801
BID 105803
BID 105805
BID 105808
BID 105813
BID 105846
CVE CVE-2018-8256
CVE CVE-2018-8407
CVE CVE-2018-8408
CVE CVE-2018-8415
CVE CVE-2018-8417
CVE CVE-2018-8450
CVE CVE-2018-8471
CVE CVE-2018-8476
CVE CVE-2018-8485
CVE CVE-2018-8542
CVE CVE-2018-8543
CVE CVE-2018-8544
CVE CVE-2018-8547
CVE CVE-2018-8549
CVE CVE-2018-8550
CVE CVE-2018-8552
CVE CVE-2018-8553
CVE CVE-2018-8555
CVE CVE-2018-8556
CVE CVE-2018-8557
CVE CVE-2018-8561
CVE CVE-2018-8562
CVE CVE-2018-8564
CVE CVE-2018-8565
CVE CVE-2018-8584
CVE CVE-2018-8588
MSKB 4467691
XREF MSFT:MS18-4467691
Plugin Information
Published: 2018/11/13, Modified: 2020/08/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4467691

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2608
119584 - KB4471321: Windows 10 Version 1607 and Windows Server 2016 December 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4471321.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly. An attacker who successfully exploited this vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2018-8540)

- A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. (CVE-2018-8612)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2018-8595, CVE-2018-8596)

- A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8634)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8631)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8639)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly impersonates file operations.
(CVE-2018-8599)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8477)

- An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memory. (CVE-2018-8514)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8617, CVE-2018-8618, CVE-2018-8624, CVE-2018-8629)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8611)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8625)

- A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions. An attacker who exploited the vulnerability could run arbitrary code with medium-integrity level privileges (the permissions of the current user). (CVE-2018-8619)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8643)

- A denial of service vulnerability exists when .NET Framework improperly handles special web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework application. The update addresses the vulnerability by correcting how the .NET Framework web application handles web requests. (CVE-2018-8517)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8641)

- A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows servers that are configured as DNS servers are at risk from this vulnerability. (CVE-2018-8626)
See Also
Solution
Apply Cumulative Update KB4471321.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.8983
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2018-8477
CVE CVE-2018-8514
CVE CVE-2018-8517
CVE CVE-2018-8540
CVE CVE-2018-8595
CVE CVE-2018-8596
CVE CVE-2018-8599
CVE CVE-2018-8611
CVE CVE-2018-8612
CVE CVE-2018-8617
CVE CVE-2018-8618
CVE CVE-2018-8619
CVE CVE-2018-8624
CVE CVE-2018-8625
CVE CVE-2018-8626
CVE CVE-2018-8629
CVE CVE-2018-8631
CVE CVE-2018-8634
CVE CVE-2018-8639
CVE CVE-2018-8641
CVE CVE-2018-8643
MSKB 4471321
XREF MSFT:MS18-4471321
XREF CISA-KNOWN-EXPLOITED:2025/03/24
XREF CISA-KNOWN-EXPLOITED:2022/06/14
Plugin Information
Published: 2018/12/11, Modified: 2025/04/08
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4471321

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2665
122126 - KB4487026: Windows 10 Version 1607 and Windows Server 2016 February 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4487026. It is, therefore, affected by multiple vulnerabilities :

- An information vulnerability exists when Windows improperly discloses file information. Successful exploitation of the vulnerability could allow the attacker to read the contents of files on disk.
(CVE-2019-0636)

- A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0645)

- An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
(CVE-2019-0659)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0623)

- An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0635)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0621)

- An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the victims system. (CVE-2019-0600, CVE-2019-0601)

- A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0613)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660)

- A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. (CVE-2019-0627, CVE-2019-0631, CVE-2019-0632)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0628)

- An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.
An attacker who successfully exploited this vulnerability could test for the presence of files on disk. For an attack to be successful, an attacker must persuade a user to open a malicious website. The security update addresses the vulnerability by changing the way Internet Explorer handles objects in memory.
(CVE-2019-0676)

- A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's. An attacker who successfully exploited this vulnerability could use it to bypass security logic intended to ensure that a user-provided URL belonged to a specific hostname or a subdomain of that hostname. This could be used to cause privileged communication to be made to an untrusted service as if it was a trusted service.
(CVE-2019-0657)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0606)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0618, CVE-2019-0662)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0656)

- A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects. An attacker who successfully exploited this vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
(CVE-2019-0654)

- A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server.
(CVE-2019-0630, CVE-2019-0633)

- A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. (CVE-2019-0626)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0595, CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625)

- An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system.
(CVE-2019-0663)
See Also
Solution
Apply Cumulative Update KB4487026.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.6081
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2019/02/12, Modified: 2022/05/25
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4487026

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2791
125058 - KB4494440: Windows 10 Version 1607 and Windows Server 2016 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4494440. It is, therefore, affected by multiple vulnerabilities :

- A new subclass of speculative execution side channel vulnerabilities, known as Microarchitectural Data Sampling, exist in Windows.
An attacker who successfully exploited these vulnerabilities may be able to read privileged data across trust boundaries. In shared resource environments (such as exists in some cloud services configurations), these vulnerabilities could allow one virtual machine to improperly access information from another. In non-browsing scenarios on standalone systems, an attacker would need prior access to the system or an ability to run a specially crafted application on the target system to leverage these vulnerabilities.
(CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091)

- A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries. The vulnerability allows Internet Explorer to bypass Mark of the Web warnings or restrictions for files downloaded or created in a specific way.
(CVE-2019-0995)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0940)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902)

- An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit this vulnerability by running a specially crafted application. The security update addresses the vulnerability by helping to ensure that the Windows Kernel properly handles key enumeration. (CVE-2019-0881)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0903)

- An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0886)

- An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry. An attacker who successfully exploited the vulnerability could make changes to the registry keys protected by UWF without having administrator privileges.
(CVE-2019-0942)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933)

- A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could circumvent Windows PowerShell Constrained Language Mode on the machine. (CVE-2019-0733)

- An spoofing vulnerability exists when Internet Explorer improperly handles URLs. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. (CVE-2019-0921)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations. (CVE-2019-0727)

- An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator. The update addresses this vulnerability by changing how these requests are validated. (CVE-2019-0734)

- A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code. (CVE-2019-0885)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0884, CVE-2019-0911, CVE-2019-0918)

- An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with administrator privileges. (CVE-2019-0863)

- An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0930)

- A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET Framework (or .NET core) application. The update addresses the vulnerability by correcting how .NET Framework and .NET Core applications handle RegEx string processing. (CVE-2019-0820)

- An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. (CVE-2019-0936)

- A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. (CVE-2019-0725)

- A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. (CVE-2019-0864)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-0758, CVE-2019-0882, CVE-2019-0961)

- An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser. An attacker who successfully exploited this vulnerability could gain elevated privileges and break out of the Edge AppContainer sandbox. The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running. The security update addresses the vulnerability by modifying how Microsoft Edge handles sandboxing. (CVE-2019-0938)

- An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it. (CVE-2019-0707)

- A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests.
An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework or .NET Core application.
The update addresses the vulnerability by correcting how .NET Framework or .NET Core web applications handles web requests. (CVE-2019-0980, CVE-2019-0981)
See Also
Solution
Apply Cumulative Update KB4494440.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.465
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Plugin Information
Published: 2019/05/14, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4494440

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2969
126577 - KB4507460: Windows 10 Version 1607 and Windows Server 2016 July 2019 Security Update (SWAPGS)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4507460.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-0999)

- A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1113)

- A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. (CVE-2019-0880)

- An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. (CVE-2019-1089)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1062, CVE-2019-1092, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107)

- An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1108)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-1096)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2019-0966)

- An elevation of privilege vulnerability exists in Microsoft Windows where a certain dll, with Local Service privilege, is vulnerable to race planting a customized dll. An attacker who successfully exploited this vulnerability could potentially elevate privilege to SYSTEM. The update addresses this vulnerability by requiring system privileges for a certain DLL.
(CVE-2019-1082)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-1001)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1063)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1104)

- An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
(CVE-2019-1093, CVE-2019-1097)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-1094, CVE-2019-1095)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory. (CVE-2019-1071)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1067)

- An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2019-1086, CVE-2019-1087, CVE-2019-1088)

- An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1130)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-1004, CVE-2019-1056, CVE-2019-1059)

- A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.
(CVE-2019-1126)

- A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an authenticated attacker abuses clipboard redirection. An attacker who successfully exploited this vulnerability could execute arbitrary code on the victim system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0887)

- An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1085)

- A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET web application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET application. The update addresses the vulnerability by correcting how the .NET web application handles web requests. (CVE-2019-1083)

- A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server. An attacker who successfully exploited the vulnerability could either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive.
(CVE-2019-0785)

- A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses.
(CVE-2019-0975)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1073)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1102)

- An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys. This vulnerability allows an attacker to impersonate another user, which can lead to elevation of privileges. The vulnerability exists in WCF, WIF 3.5 and above in .NET Framework, WIF 1.0 component in Windows, WIF Nuget package, and WIF implementation in SharePoint. An unauthenticated attacker can exploit this by signing a SAML token with any arbitrary symmetric key. This security update addresses the issue by ensuring all versions of WCF and WIF validate the key used to sign SAML tokens correctly.
(CVE-2019-1006)

- An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory.
An attacker who successfully exploited the vulnerability could potentially disclose memory contents of an elevated process. (CVE-2019-1091)

- A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries. An attacker who successfully exploited this vulnerability could cause the DNS Server service to become nonresponsive. (CVE-2019-0811)
- An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. (CVE-2019-1125)
See Also
Solution
Apply Cumulative Update KB4507460.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.5322
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Plugin Information
Published: 2019/07/09, Modified: 2022/05/25
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4507460

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3085
127850 - KB4512517: Windows 10 Version 1607 and Windows Server 2016 August 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4512517.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1162)

- A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the vulnerability could force the browser to send data that would otherwise be restricted.
(CVE-2019-1192)

- An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-1148, CVE-2019-1153)

- A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application. The update addresses the vulnerability by correcting how the XmlLite runtime parses XML input. (CVE-2019-1187)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1176)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1146, CVE-2019-1147, CVE-2019-1155, CVE-2019-1156, CVE-2019-1157)

- A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. (CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9518)

- <h1>Executive Summary</h1> Microsoft is aware of the Bluetooth BR/EDR (basic rate/enhanced data rate, known as &quot;Bluetooth Classic&quot;) key negotiation vulnerability that exists at the hardware specification level of any BR/EDR Bluetooth device. An attacker could potentially be able to negotiate the offered key length down to 1 byte of entropy, from a maximum of 16 bytes.
(CVE-2019-9506)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1139, CVE-2019-1140, CVE-2019-1195, CVE-2019-1197)

- An elevation of privilege exists in the p2pimsvc service where an attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2019-1168)

- An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows Graphics Component handles objects in memory. (CVE-2019-1078)

- An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1180, CVE-2019-1186)

- A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server. An attacker who successfully exploited the vulnerability could cause the DHCP service to become nonresponsive.
(CVE-2019-1206)

- An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1179)

- An elevation of privilege exists in SyncController.dll.
An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
(CVE-2019-1198)

- An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1178)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1144, CVE-2019-1145, CVE-2019-1149, CVE-2019-1150, CVE-2019-1151, CVE-2019-1152)

- A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. (CVE-2019-1163)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1159, CVE-2019-1164)

- A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests.
This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1181, CVE-2019-1182)

- A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. (CVE-2019-0736)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-1133, CVE-2019-1194)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1183)

- An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1177)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1193)

- An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-1030)

- An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. (CVE-2019-1172)

- A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. (CVE-2019-0714, CVE-2019-0715, CVE-2019-0718, CVE-2019-0723)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-0716)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document or by convincing a user to visit an untrusted webpage.
The update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
(CVE-2019-1143, CVE-2019-1158)

- A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0720)

- A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. (CVE-2019-1212)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2019-1057)
See Also
Solution
Apply Cumulative Update KB4512517.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.7829
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2019/08/13, Modified: 2024/05/30
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4512517

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3143
129719 - KB4519998: Windows 10 Version 1607 and Windows Server 2016 October 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4519998.
It is, therefore, affected by multiple vulnerabilities :

- A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could impersonate a user request by crafting HTTP queries. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. (CVE-2019-0608)

- A denial of service vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-1317)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1307, CVE-2019-1308, CVE-2019-1335)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-1343, CVE-2019-1346, CVE-2019-1347)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status. (CVE-2019-1342)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1238)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1371)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1334, CVE-2019-1345)

- A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions. An attacker who successfully exploited this vulnerability may gain access to unauthorized information. (CVE-2019-1318)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2019-1060)

- An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. (CVE-2019-1356)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1358, CVE-2019-1359)

- A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1333)

- A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. (CVE-2019-1166)

- An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems. When this vulnerability is exploited within other versions of Windows it can cause a denial of service, but not an elevation of privilege. (CVE-2019-1325)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. (CVE-2019-1315, CVE-2019-1339)

- An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it. An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.
The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests. (CVE-2019-1365)

- A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies. An attacker who successfully exploited this vulnerability could trick a browser into overwriting a secure cookie with an insecure cookie. The insecure cookie could serve as a pivot to chain an attack with other vulnerabilities in web services. (CVE-2019-1357)

- An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1316)

- An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1344)

- A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. (CVE-2019-1311)

- A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding. (CVE-2019-1326)

- An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function. An attacker who successfully exploited this vulnerability could delete a targeted registry key leading to an elevated status.
(CVE-2019-1341)

- An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. (CVE-2019-1319)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1366)
See Also
Solution
Apply Cumulative Update KB4519998.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.5636
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2019/10/08, Modified: 2023/03/08
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4519998

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3269
130906 - KB4525236: Windows 10 Version 1607 and Windows Server 2016 November 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4525236. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0719)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-1389, CVE-2019-1397)

- A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel. An attacker who successfully exploited the vulnerability could downgrade aspects of the connection allowing for further modification of the transmission. (CVE-2019-1424)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-11135)

- An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1374)

- An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1388)

- A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls.. (CVE-2019-1380)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-1429)

- A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. (CVE-2019-1384)

- An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2019-1407, CVE-2019-1433, CVE-2019-1435, CVE-2019-1438)

- An information vulnerability exists when Windows Modules Installer Service improperly discloses file information.
Successful exploitation of the vulnerability could allow the attacker to read the contents of a log file on disk.
(CVE-2019-1418)

- An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. (CVE-2019-1454)

- A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. (CVE-2019-0712)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2018-12207, CVE-2019-1391)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408)

- An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. (CVE-2019-1415)

- An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
(CVE-2019-1411)

- An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations. An attacker who successfully exploited the vulnerability could potentially access unauthorized files. (CVE-2019-1381)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1390)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-1436)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-1439)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1406)

- An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1405)

- A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by either convincing a user to open a specially crafted document, or by convincing a user to visit a webpage that contains specially crafted embedded OpenType fonts. The update addresses the vulnerability by correcting how the Windows Adobe Type Manager Library handles OpenType fonts. (CVE-2019-1419, CVE-2019-1456)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2019-1399)

- An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Data Sharing Service handles file operations. (CVE-2019-1383, CVE-2019-1417)

- An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication. An attacker who successfully exploited the vulnerability could potentially access unauthorized files. (CVE-2019-1382)

- An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system.
(CVE-2019-1409)

- An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1420)

- An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2019-1422)
See Also
Solution
Apply Cumulative Update KB4525236.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.7447
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2019/11/12, Modified: 2023/04/08
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4525236

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3321
132858 - KB4534271: Windows 10 Version 1607 and Windows Server 2016 January 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4534271.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0609, CVE-2020-0610)

- An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information. An attacker who successfully exploited this vulnerability could obtain legitimate users'
credentials. (CVE-2020-0637)

- An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to obtain information that could be used to try to further compromise the affected system. (CVE-2020-0615, CVE-2020-0639)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0642)

- A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0605, CVE-2020-0606)

- A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2020-0617)

- An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. (CVE-2020-0635)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. (CVE-2020-0643)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-0640)

- A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD Gateway service on the target system to stop responding.
(CVE-2020-0612)

- An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0622)

- An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0608)

- An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files. An attacker could exploit the vulnerability to overwrite or modify a protected file leading to a privilege escalation. (CVE-2020-0620)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0634)

- An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. (CVE-2020-0641)

- An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information that could be useful for further exploitation. (CVE-2020-0607)

- A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly. An attacker who successfully exploited this vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2020-0646)

- A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0611)

- An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names. An attacker who successfully exploited this vulnerability could run arbitrary code as system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0644)

- A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code- signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider. A successful exploit could also allow the attacker to conduct man-in- the-middle attacks and decrypt confidential information on user connections to the affected software. The security update addresses the vulnerability by ensuring that Windows CryptoAPI completely validates ECC certificates. (CVE-2020-0601)
See Also
Solution
Apply Cumulative Update KB4534271.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.9409
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-0601
CVE CVE-2020-0605
CVE CVE-2020-0606
CVE CVE-2020-0607
CVE CVE-2020-0608
CVE CVE-2020-0609
CVE CVE-2020-0610
CVE CVE-2020-0611
CVE CVE-2020-0612
CVE CVE-2020-0613
CVE CVE-2020-0614
CVE CVE-2020-0615
CVE CVE-2020-0617
CVE CVE-2020-0620
CVE CVE-2020-0622
CVE CVE-2020-0623
CVE CVE-2020-0625
CVE CVE-2020-0626
CVE CVE-2020-0627
CVE CVE-2020-0628
CVE CVE-2020-0629
CVE CVE-2020-0630
CVE CVE-2020-0631
CVE CVE-2020-0632
CVE CVE-2020-0633
CVE CVE-2020-0634
CVE CVE-2020-0635
CVE CVE-2020-0637
CVE CVE-2020-0639
CVE CVE-2020-0640
CVE CVE-2020-0641
CVE CVE-2020-0642
CVE CVE-2020-0643
CVE CVE-2020-0644
CVE CVE-2020-0646
MSKB 4534271
XREF IAVA:2020-A-0010
XREF CISA-KNOWN-EXPLOITED:2022/05/03
XREF MSFT:MS20-4534271
XREF CEA-ID:CEA-2020-0129
XREF CEA-ID:CEA-2020-0014
XREF CEA-ID:CEA-2020-0009
Exploitable With
CANVAS (true) Metasploit (true)
Plugin Information
Published: 2020/01/14, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4534271

- C:\Windows\system32\crypt32.dll has not been patched.
Remote version : 10.0.14393.2214
Should be : 10.0.14393.3442
134369 - KB4540670: Windows 10 Version 1607 and Windows Server 2016 March 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4540670.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the Windows Device Setup Manager improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Device Setup Manager handles file operations. (CVE-2020-0819)

- An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Work Folder Service handles file operations. (CVE-2020-0777, CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-0824)

- An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. (CVE-2020-0814, CVE-2020-0842, CVE-2020-0843)

- An information vulnerability exists when Windows Modules Installer Service improperly discloses file information.
Successful exploitation of the vulnerability could allow the attacker to read any file on the file system.
(CVE-2020-0859)

- An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
(CVE-2020-0787)

- An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could potentially disclose memory contents of an elevated process. (CVE-2020-0871)

- An elevation of privilege vulnerability exists when the &quot;Public Account Pictures&quot; folder improperly handles junctions. (CVE-2020-0858)

- A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers. An attacker who successfully exploited the vulnerability could cause a vulnerable server to improperly process HTTP headers and tamper with the responses returned to clients. (CVE-2020-0645)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0788, CVE-2020-0877, CVE-2020-0887)

- An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0778, CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845)

- An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. (CVE-2020-0798)

- An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links. An attacker who successfully exploited this vulnerability could potentially access privileged registry keys and thereby elevate permissions. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0799)

- An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service handles file operations. (CVE-2020-0844)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations. (CVE-2020-0810)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-0801, CVE-2020-0809, CVE-2020-0869)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2020-0684)

- An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
(CVE-2020-0840, CVE-2020-0841, CVE-2020-0849, CVE-2020-0896)

- An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. (CVE-2020-0785)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. (CVE-2020-0874, CVE-2020-0879)

- An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0857)

- An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. (CVE-2020-0806)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-0774, CVE-2020-0880, CVE-2020-0882)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0881, CVE-2020-0883)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document or by convincing a user to visit an untrusted webpage.
The update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
(CVE-2020-0885)

- An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory.
An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An attacker who had already gained execution on the victim system could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how Media Foundation handles objects in memory. (CVE-2020-0820)

- An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Language Pack Installer handles file operations. (CVE-2020-0822)

- An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0780)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0834)

- An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0781, CVE-2020-0783)

- An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0791, CVE-2020-0898)

- An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory. (CVE-2020-0861)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0690)

- A denial of service vulnerability exists when the Windows Tile Object Service improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2020-0786)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2020-0832, CVE-2020-0833)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2020-0768, CVE-2020-0830)

- An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files. (CVE-2020-0779)

- An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations. (CVE-2020-0776)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-0847)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly handles file operations. (CVE-2020-0793)

- An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations. (CVE-2020-0775)

- An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.
(CVE-2020-0769, CVE-2020-0771)

- An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory. An attacker who succesfully exploited this vulnerability could obtain information to further compromise the user's system.
There are multiple ways an attacker could exploit this vulnerability: (CVE-2020-0853)

- An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Update Orchestrator Service handles file operations. (CVE-2020-0867, CVE-2020-0868)

- An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory. (CVE-2020-0770, CVE-2020-0773, CVE-2020-0860)

- An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles memory.
(CVE-2020-0772)

- A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0816)

- A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-08323, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0848)
See Also
Solution
Apply Cumulative Update KB4540670.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.7244
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-0645
CVE CVE-2020-0684
CVE CVE-2020-0690
CVE CVE-2020-0768
CVE CVE-2020-0769
CVE CVE-2020-0770
CVE CVE-2020-0771
CVE CVE-2020-0772
CVE CVE-2020-0773
CVE CVE-2020-0774
CVE CVE-2020-0775
CVE CVE-2020-0776
CVE CVE-2020-0777
CVE CVE-2020-0778
CVE CVE-2020-0779
CVE CVE-2020-0780
CVE CVE-2020-0781
CVE CVE-2020-0783
CVE CVE-2020-0785
CVE CVE-2020-0786
CVE CVE-2020-0787
CVE CVE-2020-0788
CVE CVE-2020-0791
CVE CVE-2020-0793
CVE CVE-2020-0797
CVE CVE-2020-0798
CVE CVE-2020-0799
CVE CVE-2020-0800
CVE CVE-2020-0801
CVE CVE-2020-0802
CVE CVE-2020-0803
CVE CVE-2020-0804
CVE CVE-2020-0806
CVE CVE-2020-0809
CVE CVE-2020-0810
CVE CVE-2020-0814
CVE CVE-2020-0816
CVE CVE-2020-0819
CVE CVE-2020-0820
CVE CVE-2020-0822
CVE CVE-2020-0823
CVE CVE-2020-0824
CVE CVE-2020-0826
CVE CVE-2020-0827
CVE CVE-2020-0828
CVE CVE-2020-0829
CVE CVE-2020-0830
CVE CVE-2020-0831
CVE CVE-2020-0832
CVE CVE-2020-0833
CVE CVE-2020-0834
CVE CVE-2020-0840
CVE CVE-2020-0841
CVE CVE-2020-0842
CVE CVE-2020-0843
CVE CVE-2020-0844
CVE CVE-2020-0845
CVE CVE-2020-0847
CVE CVE-2020-0848
CVE CVE-2020-0849
CVE CVE-2020-0853
CVE CVE-2020-0857
CVE CVE-2020-0858
CVE CVE-2020-0859
CVE CVE-2020-0860
CVE CVE-2020-0861
CVE CVE-2020-0864
CVE CVE-2020-0865
CVE CVE-2020-0866
CVE CVE-2020-0867
CVE CVE-2020-0868
CVE CVE-2020-0869
CVE CVE-2020-0871
CVE CVE-2020-0874
CVE CVE-2020-0877
CVE CVE-2020-0879
CVE CVE-2020-0880
CVE CVE-2020-0881
CVE CVE-2020-0882
CVE CVE-2020-0883
CVE CVE-2020-0885
CVE CVE-2020-0887
CVE CVE-2020-0896
CVE CVE-2020-0897
CVE CVE-2020-0898
MSKB 4540670
XREF MSFT:MS20-4540670
XREF IAVA:2020-A-0139-S
XREF IAVA:2020-A-0214-S
XREF CISA-KNOWN-EXPLOITED:2022/07/28
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/03/10, Modified: 2023/02/20
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4540670

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3564
136505 - KB4556813: Windows 10 Version 1607 and Windows Server 2016 May 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4556813.
It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. (CVE-2020-1108)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2020-1076)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. (CVE-2020-1141)

- An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. (CVE-2020-1021, CVE-2020-1082, CVE-2020-1088)

- A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. (CVE-2020-0909)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1072)

- A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could cause a system to stop responding. (CVE-2020-1123)

- A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. (CVE-2020-1084)

- An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1048, CVE-2020-1070)

- An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations.
(CVE-2020-1010)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1051, CVE-2020-1174, CVE-2020-1175, CVE-2020-1176)

- An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1079)

- An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. (CVE-2020-1078)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1062, CVE-2020-1092)

- An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
(CVE-2020-1138)

- A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. (CVE-2020-1064)

- An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
(CVE-2020-1077, CVE-2020-1086, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164)

- An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. (CVE-2020-1056)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-0963, CVE-2020-1179)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-1028, CVE-2020-1126, CVE-2020-1136)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-1153)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1054, CVE-2020-1143)

- A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. (CVE-2020-1067)

- A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1117)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. (CVE-2020-1132)

- A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1113)

- An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder. (CVE-2020-1112)

- An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers. An authenticated attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges.
(CVE-2020-1081)

- A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1061)

- An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows State Repository Service handles objects in memory.
(CVE-2020-1124, CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189, CVE-2020-1190, CVE-2020-1191)

- An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2020-1071)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1037)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1114)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1154)

- An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. (CVE-2020-1068)

- An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system.
(CVE-2020-1116)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1035, CVE-2020-1058, CVE-2020-1060, CVE-2020-1093)
See Also
Solution
Apply Cumulative Update KB4556813.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.8234
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/05/12, Modified: 2023/01/27
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4556813

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3686
142690 - KB4586830: Windows 10 Version 1607 and Windows Server 2016 November 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft 4586830 Product is missing security updates.

- Remote Desktop Protocol Server Information Disclosure Vulnerability (CVE-2020-16997)

- DirectX Elevation of Privilege Vulnerability (CVE-2020-16998)

- Windows WalletService Information Disclosure Vulnerability (CVE-2020-16999)

- Remote Desktop Protocol Client Information Disclosure Vulnerability (CVE-2020-17000)

- Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17014.
(CVE-2020-17001)

- Windows Graphics Component Information Disclosure Vulnerability (CVE-2020-17004)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044. (CVE-2020-17055)

- Windows Network File System Information Disclosure Vulnerability (CVE-2020-17056)

- Windows Win32k Elevation of Privilege Vulnerability (CVE-2020-17057)

- Windows GDI+ Remote Code Execution Vulnerability (CVE-2020-17068)

- Windows NDIS Information Disclosure Vulnerability (CVE-2020-17069)

- Windows Delivery Optimization Information Disclosure Vulnerability (CVE-2020-17071)

- Windows USO Core Worker Elevation of Privilege Vulnerability (CVE-2020-17075)

- Windows Kernel Local Elevation of Privilege Vulnerability (CVE-2020-17087)

- Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2020-17088)

- Windows Camera Codec Information Disclosure Vulnerability (CVE-2020-17113)

- Windows Spoofing Vulnerability (CVE-2020-1599)

- Windows Error Reporting Elevation of Privilege Vulnerability (CVE-2020-17007)

- Windows Port Class Library Elevation of Privilege Vulnerability (CVE-2020-17011)

- Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17001.
(CVE-2020-17014)

- Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability (CVE-2020-17024)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17025)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17026)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17027)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17028)

- Windows Canonical Display Driver Information Disclosure Vulnerability (CVE-2020-17029)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17031)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17032)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17033)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17043, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17034)

- Windows Kernel Elevation of Privilege Vulnerability (CVE-2020-17035)

- Windows Function Discovery SSDP Provider Information Disclosure Vulnerability (CVE-2020-17036)

- Windows WalletService Elevation of Privilege Vulnerability (CVE-2020-17037)

- Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17010. (CVE-2020-17038)

- Windows Hyper-V Security Feature Bypass Vulnerability (CVE-2020-17040)

- Windows Print Configuration Elevation of Privilege Vulnerability (CVE-2020-17041)

- Windows Print Spooler Remote Code Execution Vulnerability (CVE-2020-17042)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17044, CVE-2020-17055. (CVE-2020-17043)

- Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17055. (CVE-2020-17044)

- Windows KernelStream Information Disclosure Vulnerability (CVE-2020-17045)

- Windows Error Reporting Denial of Service Vulnerability (CVE-2020-17046)

- Windows Network File System Denial of Service Vulnerability (CVE-2020-17047)

- Chakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17054.
(CVE-2020-17048)

- Kerberos Security Feature Bypass Vulnerability (CVE-2020-17049)

- Windows Network File System Remote Code Execution Vulnerability (CVE-2020-17051)

- Scripting Engine Memory Corruption Vulnerability (CVE-2020-17052)

- Chakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17048.
(CVE-2020-17054)

- Microsoft Browser Memory Corruption Vulnerability (CVE-2020-17058)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Cumulative Update KB4586830.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.2175
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1599
CVE CVE-2020-16997
CVE CVE-2020-16998
CVE CVE-2020-16999
CVE CVE-2020-17000
CVE CVE-2020-17001
CVE CVE-2020-17004
CVE CVE-2020-17007
CVE CVE-2020-17011
CVE CVE-2020-17014
CVE CVE-2020-17024
CVE CVE-2020-17025
CVE CVE-2020-17026
CVE CVE-2020-17027
CVE CVE-2020-17028
CVE CVE-2020-17029
CVE CVE-2020-17031
CVE CVE-2020-17032
CVE CVE-2020-17033
CVE CVE-2020-17034
CVE CVE-2020-17035
CVE CVE-2020-17036
CVE CVE-2020-17037
CVE CVE-2020-17038
CVE CVE-2020-17040
CVE CVE-2020-17041
CVE CVE-2020-17042
CVE CVE-2020-17043
CVE CVE-2020-17044
CVE CVE-2020-17045
CVE CVE-2020-17046
CVE CVE-2020-17047
CVE CVE-2020-17048
CVE CVE-2020-17049
CVE CVE-2020-17051
CVE CVE-2020-17052
CVE CVE-2020-17054
CVE CVE-2020-17055
CVE CVE-2020-17056
CVE CVE-2020-17057
CVE CVE-2020-17058
CVE CVE-2020-17068
CVE CVE-2020-17069
CVE CVE-2020-17071
CVE CVE-2020-17075
CVE CVE-2020-17087
CVE CVE-2020-17088
CVE CVE-2020-17113
MSKB 4586830
XREF MSFT:MS20-4586830
XREF IAVA:2020-A-0512-S
XREF IAVA:2020-A-0513-S
XREF IAVA:2020-A-0518-S
XREF IAVA:2020-A-0521-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
XREF CEA-ID:CEA-2020-0135
XREF CEA-ID:CEA-2020-0124
Plugin Information
Published: 2020/11/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4586830

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4046
144882 - KB4598243: Windows 10 Version 1607 and Windows Server 2016 January 2021 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Windows AppX Deployment Extensions Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1685. (CVE-2021-1642)

- Windows DNS Query Information Disclosure Vulnerability (CVE-2021-1637)

- Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1680. (CVE-2021-1651)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693. (CVE-2021-1652)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693. (CVE-2021-1653)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1653, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693. (CVE-2021-1654)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1653, CVE-2021-1654, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693. (CVE-2021-1655)

- TPM Device Driver Information Disclosure Vulnerability (CVE-2021-1656)

- Windows Fax Compose Form Remote Code Execution Vulnerability (CVE-2021-1657)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1658)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1688, CVE-2021-1693. (CVE-2021-1659)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1660)

- Windows Installer Elevation of Privilege Vulnerability (CVE-2021-1661)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1664)

- GDI+ Remote Code Execution Vulnerability (CVE-2021-1665)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1666)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1667)

- Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability (CVE-2021-1668)

- Windows Remote Desktop Security Feature Bypass Vulnerability (CVE-2021-1669)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1673, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1671)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1700, CVE-2021-1701. (CVE-2021-1673)

- Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability (CVE-2021-1674)

- Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability (CVE-2021-1676)

- Windows CryptoAPI Denial of Service Vulnerability (CVE-2021-1679)

- Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1651. (CVE-2021-1680)

- Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1686, CVE-2021-1687, CVE-2021-1690. (CVE-2021-1681)

- Windows Bluetooth Security Feature Bypass Vulnerability This CVE ID is unique from CVE-2021-1638, CVE-2021-1684. (CVE-2021-1683)

- Windows Bluetooth Security Feature Bypass Vulnerability This CVE ID is unique from CVE-2021-1638, CVE-2021-1683. (CVE-2021-1684)

- Windows AppX Deployment Extensions Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1642. (CVE-2021-1685)

- Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1681, CVE-2021-1687, CVE-2021-1690. (CVE-2021-1686)

- Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1681, CVE-2021-1686, CVE-2021-1690. (CVE-2021-1687)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1693. (CVE-2021-1688)

- Windows Multipoint Management Elevation of Privilege Vulnerability (CVE-2021-1689)

- Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1681, CVE-2021-1686, CVE-2021-1687. (CVE-2021-1690)

- Hyper-V Denial of Service Vulnerability This CVE ID is unique from CVE-2021-1691. (CVE-2021-1692)

- Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1652, CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688. (CVE-2021-1693)

- Windows Update Stack Elevation of Privilege Vulnerability (CVE-2021-1694)

- Windows Print Spooler Elevation of Privilege Vulnerability (CVE-2021-1695)

- Windows Graphics Component Information Disclosure Vulnerability (CVE-2021-1696)

- Windows InstallService Elevation of Privilege Vulnerability (CVE-2021-1697)

- Windows GDI+ Information Disclosure Vulnerability (CVE-2021-1708)

- Windows Win32k Elevation of Privilege Vulnerability (CVE-2021-1709)

- Microsoft Windows Media Foundation Remote Code Execution Vulnerability (CVE-2021-1710)

- Windows Runtime C++ Template Library Elevation of Privilege Vulnerability (CVE-2021-1650)

- Active Template Library Elevation of Privilege Vulnerability (CVE-2021-1649)

- Microsoft splwow64 Elevation of Privilege Vulnerability (CVE-2021-1648)

- Windows Docker Information Disclosure Vulnerability (CVE-2021-1645)

- NTLM Security Feature Bypass Vulnerability (CVE-2021-1678)

- Windows (modem.sys) Information Disclosure Vulnerability (CVE-2021-1699)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1701. (CVE-2021-1700)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1658, CVE-2021-1660, CVE-2021-1664, CVE-2021-1666, CVE-2021-1667, CVE-2021-1671, CVE-2021-1673, CVE-2021-1700. (CVE-2021-1701)

- Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability (CVE-2021-1702)

- Windows Hyper-V Elevation of Privilege Vulnerability (CVE-2021-1704)

- Microsoft Edge (HTML-based) Memory Corruption Vulnerability (CVE-2021-1705)

- Windows LUAFV Elevation of Privilege Vulnerability (CVE-2021-1706)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Cumulative Update KB4598243.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.6343
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2021/01/12, Modified: 2024/11/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4598243

- C:\Windows\system32\gdiplus.dll has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4168
146329 - KB4601318: Windows 10 Version 1607 and Windows Server 2016 February 2021 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4601318.
It is, therefore, affected by multiple vulnerabilities :

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-24080, CVE-2021-24086, CVE-2021-24111)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-24082)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-1734, CVE-2021-24076, CVE-2021-24079)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-1727, CVE-2021-24096, CVE-2021-24102, CVE-2021-24103, CVE-2021-25195)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-1722, CVE-2021-24074, CVE-2021-24077, CVE-2021-24078, CVE-2021-24081, CVE-2021-24083, CVE-2021-24088, CVE-2021-24091, CVE-2021-24093, CVE-2021-24094)
See Also
Solution
Apply Cumulative Update KB4601318.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4062
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1722
CVE CVE-2021-1727
CVE CVE-2021-1734
CVE CVE-2021-24074
CVE CVE-2021-24076
CVE CVE-2021-24077
CVE CVE-2021-24078
CVE CVE-2021-24079
CVE CVE-2021-24080
CVE CVE-2021-24081
CVE CVE-2021-24082
CVE CVE-2021-24083
CVE CVE-2021-24086
CVE CVE-2021-24088
CVE CVE-2021-24091
CVE CVE-2021-24093
CVE CVE-2021-24094
CVE CVE-2021-24096
CVE CVE-2021-24102
CVE CVE-2021-24103
CVE CVE-2021-24111
CVE CVE-2021-25195
MSKB 4601318
XREF MSFT:MS21-4601318
XREF IAVA:2021-A-0072-S
XREF IAVA:2021-A-0079-S
XREF IAVA:2021-A-0093-S
Plugin Information
Published: 2021/02/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4601318

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4225
151592 - KB5004238: Windows 10 Version 1607 / Windows Server 2016 Security Update (July 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5004238. It is, therefore, affected by multiple vulnerabilities.
Solution
Apply Cumulative Update 5004238
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.1713
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2021/07/13, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5004238

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4530
152434 - KB5005043: Windows 10 Version 1607 and Windows Server 2016 Security Update (August 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5005043.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-26424, CVE-2021-26432, CVE-2021-34530, CVE-2021-34533, CVE-2021-34534, CVE-2021-34535, CVE-2021-36936, CVE-2021-36937, CVE-2021-36947)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2021-36942)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-26425, CVE-2021-26426, CVE-2021-34483, CVE-2021-34484, CVE-2021-34487, CVE-2021-34536, CVE-2021-34537)

- An memory corruption vulnerability exists. An attacker can exploit this to corrupt the memory and cause unexpected behaviors within the system/application.
(CVE-2021-34480)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-26433, CVE-2021-36926, CVE-2021-36932, CVE-2021-36933, CVE-2021-36938)
See Also
Solution
Apply Cumulative Update KB5005043.
Risk Factor
High
CVSS v3.0 Base Score
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.9355
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.5 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-26424
CVE CVE-2021-26425
CVE CVE-2021-26426
CVE CVE-2021-26432
CVE CVE-2021-26433
CVE CVE-2021-34480
CVE CVE-2021-34481
CVE CVE-2021-34483
CVE CVE-2021-34484
CVE CVE-2021-34487
CVE CVE-2021-34530
CVE CVE-2021-34533
CVE CVE-2021-34534
CVE CVE-2021-34535
CVE CVE-2021-34536
CVE CVE-2021-34537
CVE CVE-2021-36926
CVE CVE-2021-36932
CVE CVE-2021-36933
CVE CVE-2021-36936
CVE CVE-2021-36937
CVE CVE-2021-36938
CVE CVE-2021-36942
CVE CVE-2021-36947
MSKB 5005043
XREF MSFT:MS21-5005043
XREF IAVA:2021-A-0373-S
XREF IAVA:2021-A-0374-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
XREF CISA-KNOWN-EXPLOITED:2022/04/21
Plugin Information
Published: 2021/08/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5005043

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4583
156063 - KB5008207: Windows 10 Version 1607 and Windows Server 2016 Security Update (December 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5008207.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-43215, CVE-2021-43217, CVE-2021-43232, CVE-2021-43233, CVE-2021-43234)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-43216, CVE-2021-43222, CVE-2021-43224, CVE-2021-43227, CVE-2021-43235, CVE-2021-43236)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-41333, CVE-2021-43207, CVE-2021-43223, CVE-2021-43226, CVE-2021-43229, CVE-2021-43230, CVE-2021-43231, CVE-2021-43238, CVE-2021-43248, CVE-2021-43883, CVE-2021-43893)
See Also
Solution
Apply Cumulative Update KB5008207.
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.2366
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.5 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-41333
CVE CVE-2021-43207
CVE CVE-2021-43215
CVE CVE-2021-43216
CVE CVE-2021-43217
CVE CVE-2021-43222
CVE CVE-2021-43223
CVE CVE-2021-43224
CVE CVE-2021-43226
CVE CVE-2021-43227
CVE CVE-2021-43229
CVE CVE-2021-43230
CVE CVE-2021-43231
CVE CVE-2021-43232
CVE CVE-2021-43233
CVE CVE-2021-43234
CVE CVE-2021-43235
CVE CVE-2021-43236
CVE CVE-2021-43238
CVE CVE-2021-43248
CVE CVE-2021-43883
CVE CVE-2021-43893
MSKB 5008207
XREF MSFT:MS21-5008207
XREF IAVA:2021-A-0586-S
XREF IAVA:2021-A-0582-S
XREF CISA-KNOWN-EXPLOITED:2025/10/27
Plugin Information
Published: 2021/12/14, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5008207

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4825
156619 - KB5009546: Windows 10 Version 1607 and Windows Server 2016 Security Update (January 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5009546.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21849, CVE-2022-21850, CVE-2022-21851, CVE-2022-21874, CVE-2022-21878, CVE-2022-21892, CVE-2022-21893, CVE-2022-21922, CVE-2022-21928, CVE-2022-21958, CVE-2022-21959, CVE-2022-21960, CVE-2022-21961, CVE-2022-21962, CVE-2022-21963)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-21876, CVE-2022-21880, CVE-2022-21904, CVE-2022-21915)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-21894, CVE-2022-21900, CVE-2022-21905, CVE-2022-21913, CVE-2022-21924, CVE-2022-21925)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2022-21836)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889, CVE-2022-21890)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2022-21833, CVE-2022-21834, CVE-2022-21835, CVE-2022-21838, CVE-2022-21857, CVE-2022-21859, CVE-2022-21860, CVE-2022-21862, CVE-2022-21863, CVE-2022-21864, CVE-2022-21866, CVE-2022-21867, CVE-2022-21868, CVE-2022-21870, CVE-2022-21871, CVE-2022-21873, CVE-2022-21875, CVE-2022-21879, CVE-2022-21881, CVE-2022-21884, CVE-2022-21885, CVE-2022-21895, CVE-2022-21897, CVE-2022-21901, CVE-2022-21902, CVE-2022-21903, CVE-2022-21908, CVE-2022-21910, CVE-2022-21914, CVE-2022-21916, CVE-2022-21919, CVE-2022-21920)
See Also
Solution
Apply Cumulative Update KB5009546.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3703
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/01/11, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5009546

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4886
159677 - KB5012596: Windows 10 version 1607 / Windows Server 2016 Security Update (April 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5012591.
It is, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2022-26827, CVE-2022-24549, CVE-2022-26810, CVE-2022-26803, CVE-2022-26808, CVE-2022-26807, CVE-2022-26792, CVE-2022-26801, CVE-2022-26802, CVE-2022-26794, CVE-2022-26790, CVE-2022-26797, CVE-2022-26787, CVE-2022-26798, CVE-2022-26796, CVE-2022-26786, CVE-2022-26904, CVE-2022-26788, CVE-2022-24496, CVE-2022-24544, CVE-2022-24540, CVE-2022-24489, CVE-2022-24486, CVE-2022-24481, CVE-2022-24479, CVE-2022-24527, CVE-2022-24474, CVE-2022-24521, CVE-2022-24547, CVE-2022-24550, CVE-2022-24499, CVE-2022-24494, CVE-2022-24542, CVE-2022-24530)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-26831, CVE-2022-26915, CVE-2022-24538, CVE-2022-24484, CVE-2022-26784)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-26823, CVE-2022-26812, CVE-2022-26919, CVE-2022-26811, CVE-2022-26809, CVE-2022-26918, CVE-2022-26917, CVE-2022-26813, CVE-2022-26826, CVE-2022-26824, CVE-2022-26815, CVE-2022-26814, CVE-2022-26916, CVE-2022-26822, CVE-2022-26829, CVE-2022-26820, CVE-2022-26819, CVE-2022-26818, CVE-2022-26825, CVE-2022-26817, CVE-2022-26821, CVE-2022-24545, CVE-2022-24541, CVE-2022-24492, CVE-2022-24491, CVE-2022-24537, CVE-2022-24536, CVE-2022-24487, CVE-2022-24534, CVE-2022-24485, CVE-2022-24533, CVE-2022-26903, CVE-2022-24495, CVE-2022-24528, CVE-2022-21983, CVE-2022-22008, CVE-2022-24500)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-26816, CVE-2022-24493, CVE-2022-24539, CVE-2022-24490, CVE-2022-26783, CVE-2022-26785, CVE-2022-24498, CVE-2022-24483)
See Also
Solution
Apply Cumulative Update 5012596
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9256
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21983
CVE CVE-2022-22008
CVE CVE-2022-24474
CVE CVE-2022-24479
CVE CVE-2022-24481
CVE CVE-2022-24482
CVE CVE-2022-24483
CVE CVE-2022-24484
CVE CVE-2022-24485
CVE CVE-2022-24486
CVE CVE-2022-24487
CVE CVE-2022-24489
CVE CVE-2022-24490
CVE CVE-2022-24491
CVE CVE-2022-24492
CVE CVE-2022-24493
CVE CVE-2022-24494
CVE CVE-2022-24495
CVE CVE-2022-24496
CVE CVE-2022-24497
CVE CVE-2022-24498
CVE CVE-2022-24499
CVE CVE-2022-24500
CVE CVE-2022-24521
CVE CVE-2022-24527
CVE CVE-2022-24528
CVE CVE-2022-24530
CVE CVE-2022-24533
CVE CVE-2022-24534
CVE CVE-2022-24536
CVE CVE-2022-24537
CVE CVE-2022-24538
CVE CVE-2022-24539
CVE CVE-2022-24540
CVE CVE-2022-24541
CVE CVE-2022-24542
CVE CVE-2022-24544
CVE CVE-2022-24545
CVE CVE-2022-24547
CVE CVE-2022-24549
CVE CVE-2022-24550
CVE CVE-2022-26783
CVE CVE-2022-26784
CVE CVE-2022-26785
CVE CVE-2022-26786
CVE CVE-2022-26787
CVE CVE-2022-26788
CVE CVE-2022-26790
CVE CVE-2022-26792
CVE CVE-2022-26794
CVE CVE-2022-26796
CVE CVE-2022-26797
CVE CVE-2022-26798
CVE CVE-2022-26801
CVE CVE-2022-26802
CVE CVE-2022-26803
CVE CVE-2022-26807
CVE CVE-2022-26808
CVE CVE-2022-26809
CVE CVE-2022-26810
CVE CVE-2022-26811
CVE CVE-2022-26812
CVE CVE-2022-26813
CVE CVE-2022-26814
CVE CVE-2022-26815
CVE CVE-2022-26816
CVE CVE-2022-26817
CVE CVE-2022-26818
CVE CVE-2022-26819
CVE CVE-2022-26820
CVE CVE-2022-26821
CVE CVE-2022-26822
CVE CVE-2022-26823
CVE CVE-2022-26824
CVE CVE-2022-26825
CVE CVE-2022-26826
CVE CVE-2022-26827
CVE CVE-2022-26829
CVE CVE-2022-26831
CVE CVE-2022-26832
CVE CVE-2022-26903
CVE CVE-2022-26904
CVE CVE-2022-26915
CVE CVE-2022-26916
CVE CVE-2022-26917
CVE CVE-2022-26918
CVE CVE-2022-26919
MSKB 5012596
XREF MSFT:MS22-5012596
XREF IAVA:2022-A-0143-S
XREF IAVA:2022-A-0147-S
XREF IAVA:2022-A-0145-S
XREF CISA-KNOWN-EXPLOITED:2022/05/04
XREF CISA-KNOWN-EXPLOITED:2022/05/16
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2022/04/12, Modified: 2024/11/28
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5012596

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5066
163940 - KB5016622: Windows 10 Version 1607 and Windows Server 2016 Security Update (August 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5016622. It is, therefore, affected by multiple vulnerabilities

- Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability (CVE-2022-35747, CVE-2022-35769)

- Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability (CVE-2022-30133, CVE-2022-35744)

- Windows Bluetooth Service Remote Code Execution Vulnerability (CVE-2022-30144)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5016622
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.4615
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/08/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5016622

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5291
164996 - KB5017305: Windows 10 Version 1607 and Windows Server 2016 Security Update (September 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5017305. It is, therefore, affected by multiple vulnerabilities

- Windows Photo Import API Elevation of Privilege Vulnerability (CVE-2022-26928)

- Windows Credential Roaming Service Elevation of Privilege Vulnerability (CVE-2022-30170)

- Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability (CVE-2022-30200)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5017305
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.8578
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2022/09/13, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5017305

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5356
171448 - KB5022838: Windows 10 Version 1607 and Windows Server 2016 Security Update (February 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5022838. It is, therefore, affected by multiple vulnerabilities

- Windows iSCSI Discovery Service Remote Code Execution Vulnerability (CVE-2023-21803)

- Microsoft PostScript Printer Driver Remote Code Execution Vulnerability (CVE-2023-21684, CVE-2023-21801)

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-21685, CVE-2023-21686, CVE-2023-21799)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5022838
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.3048
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2023/02/14, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5022838

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5717
172532 - KB5023697: Windows 10 Version 1607 and Windows Server 2016 Security Update (March 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5023697. It is, therefore, affected by multiple vulnerabilities

- An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context. (CVE-2023-1017)

- An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM. (CVE-2023-1018)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability (CVE-2023-21708, CVE-2023-23405, CVE-2023-24869, CVE-2023-24908)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5023697
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.7729
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2023/03/14, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5023697

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5786
174120 - KB5025228: Windows 10 Version 1607 and Windows Server 2016 Security Update (April 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5025228. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-28275)

- Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability (CVE-2023-28250)

- Microsoft Message Queuing Remote Code Execution Vulnerability (CVE-2023-21554)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5025228
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.9216
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/04/11, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5025228

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5850
175339 - KB5026363: Windows 10 Version 1607 and Windows Server 2016 Security Update (May 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5026363. It is, therefore, affected by multiple vulnerabilities

- Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability (CVE-2023-24943)

- Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability (CVE-2023-28283)

- Server for NFS Denial of Service Vulnerability (CVE-2023-24939)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5026363
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.7946
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-24900
CVE CVE-2023-24901
CVE CVE-2023-24903
CVE CVE-2023-24932
CVE CVE-2023-24939
CVE CVE-2023-24940
CVE CVE-2023-24941
CVE CVE-2023-24942
CVE CVE-2023-24943
CVE CVE-2023-24945
CVE CVE-2023-24946
CVE CVE-2023-24947
CVE CVE-2023-24948
CVE CVE-2023-28251
CVE CVE-2023-28283
CVE CVE-2023-29324
CVE CVE-2023-29325
CVE CVE-2023-29336
MSKB 5026363
XREF MSFT:MS23-5026363
XREF IAVA:2023-A-0248-S
XREF IAVA:2023-A-0249-S
XREF CISA-KNOWN-EXPLOITED:2023/05/30
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/05/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5026363

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5921
177246 - KB5027219: Windows 10 Version 1607 and Windows Server 2016 Security Update (June 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5027219. It is, therefore, affected by multiple vulnerabilities

- Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability (CVE-2023-29363, CVE-2023-32014, CVE-2023-32015)

- Windows Collaborative Translation Framework Elevation of Privilege Vulnerability (CVE-2023-32009)

- Microsoft ODBC Driver Remote Code Execution Vulnerability (CVE-2023-29373)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5027219
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.2211
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/06/13, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5027219

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5989
178152 - KB5028169: Windows 10 Version 1607 and Windows Server 2016 Security Update (July 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5028169. It is, therefore, affected by multiple vulnerabilities

- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2023-35365, CVE-2023-35366, CVE-2023-35367)

- Windows Netlogon Information Disclosure Vulnerability (CVE-2023-21526)

- Windows Win32k Elevation of Privilege Vulnerability (CVE-2023-21756)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5028169
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.6873
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21526
CVE CVE-2023-21756
CVE CVE-2023-32033
CVE CVE-2023-32034
CVE CVE-2023-32035
CVE CVE-2023-32038
CVE CVE-2023-32039
CVE CVE-2023-32040
CVE CVE-2023-32041
CVE CVE-2023-32042
CVE CVE-2023-32043
CVE CVE-2023-32044
CVE CVE-2023-32045
CVE CVE-2023-32046
CVE CVE-2023-32049
CVE CVE-2023-32053
CVE CVE-2023-32054
CVE CVE-2023-32055
CVE CVE-2023-32057
CVE CVE-2023-32083
CVE CVE-2023-32085
CVE CVE-2023-33154
CVE CVE-2023-33163
CVE CVE-2023-33164
CVE CVE-2023-33166
CVE CVE-2023-33167
CVE CVE-2023-33168
CVE CVE-2023-33169
CVE CVE-2023-33172
CVE CVE-2023-33173
CVE CVE-2023-33174
CVE CVE-2023-35296
CVE CVE-2023-35297
CVE CVE-2023-35299
CVE CVE-2023-35300
CVE CVE-2023-35302
CVE CVE-2023-35303
CVE CVE-2023-35304
CVE CVE-2023-35305
CVE CVE-2023-35306
CVE CVE-2023-35308
CVE CVE-2023-35309
CVE CVE-2023-35310
CVE CVE-2023-35312
CVE CVE-2023-35313
CVE CVE-2023-35314
CVE CVE-2023-35316
CVE CVE-2023-35317
CVE CVE-2023-35318
CVE CVE-2023-35319
CVE CVE-2023-35320
CVE CVE-2023-35321
CVE CVE-2023-35322
CVE CVE-2023-35324
CVE CVE-2023-35325
CVE CVE-2023-35328
CVE CVE-2023-35329
CVE CVE-2023-35330
CVE CVE-2023-35331
CVE CVE-2023-35332
CVE CVE-2023-35336
CVE CVE-2023-35338
CVE CVE-2023-35339
CVE CVE-2023-35340
CVE CVE-2023-35341
CVE CVE-2023-35342
CVE CVE-2023-35344
CVE CVE-2023-35345
CVE CVE-2023-35346
CVE CVE-2023-35348
CVE CVE-2023-35350
CVE CVE-2023-35351
CVE CVE-2023-35352
CVE CVE-2023-35353
CVE CVE-2023-35356
CVE CVE-2023-35357
CVE CVE-2023-35358
CVE CVE-2023-35360
CVE CVE-2023-35361
CVE CVE-2023-35362
CVE CVE-2023-35365
CVE CVE-2023-35366
CVE CVE-2023-35367
CVE CVE-2023-36871
CVE CVE-2023-36874
MSKB 5028169
XREF CISA-KNOWN-EXPLOITED:2023/08/01
XREF MSFT:MS23-5028169
XREF IAVA:2023-A-0347-S
XREF IAVA:2023-A-0345-S
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/07/11, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5028169

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6085
179498 - KB5029242: Windows 10 Version 1607 and Windows Server 2016 Security Update (August 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5029242. It is, therefore, affected by multiple vulnerabilities

- Microsoft Message Queuing Remote Code Execution Vulnerability (CVE-2023-35385, CVE-2023-36910, CVE-2023-36911)

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36882)

- Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability (CVE-2023-35387)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5029242
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9322
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-20569
CVE CVE-2023-35359
CVE CVE-2023-35376
CVE CVE-2023-35377
CVE CVE-2023-35380
CVE CVE-2023-35381
CVE CVE-2023-35383
CVE CVE-2023-35384
CVE CVE-2023-35385
CVE CVE-2023-35386
CVE CVE-2023-35387
CVE CVE-2023-36882
CVE CVE-2023-36884
CVE CVE-2023-36889
CVE CVE-2023-36900
CVE CVE-2023-36903
CVE CVE-2023-36905
CVE CVE-2023-36906
CVE CVE-2023-36907
CVE CVE-2023-36908
CVE CVE-2023-36909
CVE CVE-2023-36910
CVE CVE-2023-36911
CVE CVE-2023-36912
CVE CVE-2023-36913
CVE CVE-2023-38172
CVE CVE-2023-38184
CVE CVE-2023-38254
MSKB 5029242
XREF MSFT:MS23-5029242
XREF IAVA:2023-A-0418-S
XREF IAVA:2023-A-0409-S
XREF IAVA:2023-A-0402-S
XREF IAVA:2023-A-0412-S
XREF IAVA:2023-A-0416-S
XREF CISA-KNOWN-EXPLOITED:2023/08/29
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/08/08, Modified: 2024/11/13
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5029242

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6167
182862 - KB5031362: Windows 10 Version 1607 and Windows Server 2016 Security Update (October 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5031362. It is, therefore, affected by multiple vulnerabilities

- The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. (CVE-2023-44487)
- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36577)

- Windows IIS Server Elevation of Privilege Vulnerability (CVE-2023-36434)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5031362
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.9443
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-29348
CVE CVE-2023-35349
CVE CVE-2023-36431
CVE CVE-2023-36434
CVE CVE-2023-36436
CVE CVE-2023-36438
CVE CVE-2023-36557
CVE CVE-2023-36563
CVE CVE-2023-36564
CVE CVE-2023-36567
CVE CVE-2023-36570
CVE CVE-2023-36571
CVE CVE-2023-36572
CVE CVE-2023-36573
CVE CVE-2023-36574
CVE CVE-2023-36575
CVE CVE-2023-36576
CVE CVE-2023-36577
CVE CVE-2023-36578
CVE CVE-2023-36579
CVE CVE-2023-36581
CVE CVE-2023-36582
CVE CVE-2023-36583
CVE CVE-2023-36584
CVE CVE-2023-36585
CVE CVE-2023-36589
CVE CVE-2023-36590
CVE CVE-2023-36591
CVE CVE-2023-36592
CVE CVE-2023-36593
CVE CVE-2023-36594
CVE CVE-2023-36596
CVE CVE-2023-36598
CVE CVE-2023-36602
CVE CVE-2023-36606
CVE CVE-2023-36697
CVE CVE-2023-36701
CVE CVE-2023-36702
CVE CVE-2023-36703
CVE CVE-2023-36706
CVE CVE-2023-36707
CVE CVE-2023-36709
CVE CVE-2023-36710
CVE CVE-2023-36711
CVE CVE-2023-36712
CVE CVE-2023-36713
CVE CVE-2023-36717
CVE CVE-2023-36718
CVE CVE-2023-36720
CVE CVE-2023-36722
CVE CVE-2023-36724
CVE CVE-2023-36726
CVE CVE-2023-36729
CVE CVE-2023-36731
CVE CVE-2023-36732
CVE CVE-2023-36743
CVE CVE-2023-36776
CVE CVE-2023-36902
CVE CVE-2023-38159
CVE CVE-2023-38166
CVE CVE-2023-41765
CVE CVE-2023-41766
CVE CVE-2023-41767
CVE CVE-2023-41768
CVE CVE-2023-41769
CVE CVE-2023-41770
CVE CVE-2023-41771
CVE CVE-2023-41773
CVE CVE-2023-41774
CVE CVE-2023-44487
MSKB 5031362
XREF MSFT:MS23-5031362
XREF IAVA:2023-A-0552-S
XREF IAVA:2023-A-0553-S
XREF CISA-KNOWN-EXPLOITED:2023/12/07
XREF CISA-KNOWN-EXPLOITED:2023/10/31
XREF CEA-ID:CEA-2024-0004
XREF IAVB:2023-B-0083-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/10/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5031362

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6343
185576 - KB5032197: Windows 10 Version 1607 and Windows Server 2016 Security Update (November 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5032197. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36402)

- Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability (CVE-2023-36397)

- Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability (CVE-2023-36028)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5032197
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9021
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36017
CVE CVE-2023-36025
CVE CVE-2023-36028
CVE CVE-2023-36036
CVE CVE-2023-36392
CVE CVE-2023-36393
CVE CVE-2023-36394
CVE CVE-2023-36395
CVE CVE-2023-36397
CVE CVE-2023-36398
CVE CVE-2023-36400
CVE CVE-2023-36401
CVE CVE-2023-36402
CVE CVE-2023-36403
CVE CVE-2023-36404
CVE CVE-2023-36405
CVE CVE-2023-36408
CVE CVE-2023-36423
CVE CVE-2023-36424
CVE CVE-2023-36425
CVE CVE-2023-36428
CVE CVE-2023-36705
CVE CVE-2023-36719
CVE CVE-2024-21315
MSKB 5032197
XREF MSFT:MS23-5032197
XREF CISA-KNOWN-EXPLOITED:2023/12/05
XREF IAVA:2023-A-0638-S
XREF IAVA:2023-A-0636-S
XREF IAVA:2024-A-0105
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/11/14, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5032197

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6451
202043 - KB5040434: Windows 10 Version 1607 / Windows Server 2016 Security Update (July 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5040434. It is, therefore, affected by multiple vulnerabilities

- RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen- prefix collision attack against MD5 Response Authenticator signature. (CVE-2024-3596)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-30013, CVE-2024-38104) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5040434
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9286
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-3596
CVE CVE-2024-28899
CVE CVE-2024-30013
CVE CVE-2024-30071
CVE CVE-2024-30079
CVE CVE-2024-30081
CVE CVE-2024-30098
CVE CVE-2024-35270
CVE CVE-2024-37969
CVE CVE-2024-37970
CVE CVE-2024-37971
CVE CVE-2024-37972
CVE CVE-2024-37973
CVE CVE-2024-37974
CVE CVE-2024-37975
CVE CVE-2024-37984
CVE CVE-2024-37986
CVE CVE-2024-37987
CVE CVE-2024-37988
CVE CVE-2024-37989
CVE CVE-2024-38010
CVE CVE-2024-38011
CVE CVE-2024-38013
CVE CVE-2024-38015
CVE CVE-2024-38017
CVE CVE-2024-38019
CVE CVE-2024-38022
CVE CVE-2024-38025
CVE CVE-2024-38027
CVE CVE-2024-38028
CVE CVE-2024-38030
CVE CVE-2024-38031
CVE CVE-2024-38033
CVE CVE-2024-38034
CVE CVE-2024-38041
CVE CVE-2024-38043
CVE CVE-2024-38044
CVE CVE-2024-38047
CVE CVE-2024-38048
CVE CVE-2024-38049
CVE CVE-2024-38050
CVE CVE-2024-38051
CVE CVE-2024-38052
CVE CVE-2024-38053
CVE CVE-2024-38054
CVE CVE-2024-38055
CVE CVE-2024-38056
CVE CVE-2024-38057
CVE CVE-2024-38058
CVE CVE-2024-38060
CVE CVE-2024-38061
CVE CVE-2024-38062
CVE CVE-2024-38064
CVE CVE-2024-38065
CVE CVE-2024-38066
CVE CVE-2024-38067
CVE CVE-2024-38068
CVE CVE-2024-38069
CVE CVE-2024-38070
CVE CVE-2024-38071
CVE CVE-2024-38072
CVE CVE-2024-38073
CVE CVE-2024-38074
CVE CVE-2024-38076
CVE CVE-2024-38077
CVE CVE-2024-38079
CVE CVE-2024-38085
CVE CVE-2024-38091
CVE CVE-2024-38099
CVE CVE-2024-38100
CVE CVE-2024-38101
CVE CVE-2024-38102
CVE CVE-2024-38104
CVE CVE-2024-38105
CVE CVE-2024-38112
CVE CVE-2024-38517
CVE CVE-2024-39684
MSKB 5040434
XREF MSFT:MS24-5040434
XREF CISA-KNOWN-EXPLOITED:2024/07/30
XREF IAVA:2024-A-0408-S
XREF IAVA:2024-A-0407-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/07/09, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5040434

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7155
205447 - KB5041773: Windows 10 Version 1607 / Windows Server 2016 Security Update (August 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5041773. It is, therefore, affected by multiple vulnerabilities

- An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS) including a subset of Azure Virtual Machine SKUS. This can allow an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. (CVE-2024-21302)

- A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism. (CVE-2022-2601)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5041773
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9006
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/08/13, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5041773

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7254
206902 - KB5043051: Windows 10 Version 1607 / Windows Server 2016 Security Update (September 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5043051. It is, therefore, affected by multiple vulnerabilities

- Windows MSHTML Platform Spoofing Vulnerability (CVE-2024-43461)

- Windows Remote Desktop Licensing Service Spoofing Vulnerability (CVE-2024-43455)

- Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability (CVE-2024-38260, CVE-2024-38263, CVE-2024-43454, CVE-2024-43467)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5043051
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2639
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/09/10, Modified: 2025/10/22
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5043051

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7330
208298 - KB5044293: Windows 10 Version 1607 / Windows Server 2016 Security Update (October 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5044293. It is, therefore, affected by multiple vulnerabilities

- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2024-38212, CVE-2024-38261, CVE-2024-38265, CVE-2024-43453, CVE-2024-43549, CVE-2024-43564, CVE-2024-43589, CVE-2024-43592, CVE-2024-43593, CVE-2024-43607, CVE-2024-43608, CVE-2024-43611)

- Windows Netlogon Elevation of Privilege Vulnerability (CVE-2024-38124)

- Remote Desktop Client Remote Code Execution Vulnerability (CVE-2024-43599)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5044293
Risk Factor
Critical
CVSS v3.0 Base Score
9.0 (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.6 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.5847
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/10/08, Modified: 2024/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5044293

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7426
210850 - KB5046612: Windows 10 Version 1607 / Windows Server 2016 Security Update (November 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5046612. It is, therefore, affected by multiple vulnerabilities

- Windows Kerberos Remote Code Execution Vulnerability (CVE-2024-43639)

- Windows NT OS Kernel Elevation of Privilege Vulnerability (CVE-2024-43623)

- Windows Telephony Service Elevation of Privilege Vulnerability (CVE-2024-43626)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5046612
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
10.0
EPSS Score
0.9039
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38203
CVE CVE-2024-43449
CVE CVE-2024-43450
CVE CVE-2024-43451
CVE CVE-2024-43620
CVE CVE-2024-43621
CVE CVE-2024-43622
CVE CVE-2024-43623
CVE CVE-2024-43626
CVE CVE-2024-43627
CVE CVE-2024-43628
CVE CVE-2024-43634
CVE CVE-2024-43635
CVE CVE-2024-43636
CVE CVE-2024-43637
CVE CVE-2024-43638
CVE CVE-2024-43639
CVE CVE-2024-43641
CVE CVE-2024-43643
CVE CVE-2024-43644
CVE CVE-2024-43645
CVE CVE-2024-43646
CVE CVE-2024-49019
CVE CVE-2024-49039
CVE CVE-2024-49046
MSKB 5046612
XREF MSFT:MS24-5046612
XREF CISA-KNOWN-EXPLOITED:2024/12/03
XREF IAVA:2024-A-0729-S
XREF IAVA:2024-A-0730-S
Plugin Information
Published: 2024/11/12, Modified: 2025/01/23
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5046612

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7513
249125 - KB5063871: Windows 10 Version 1607 / Windows Server 2016 Security Update (August 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5063871. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
(CVE-2025-53766)

- Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. (CVE-2025-49751)

- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. (CVE-2025-49743)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5063871
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5063871

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8330
270384 - KB5066836: Windows 10 Version 1607 / Windows Server 2016 Security Update (October 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5066836. It is, therefore, affected by multiple vulnerabilities

- tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka Predictor heap-buffer-overflow. (CVE-2016-9535)

- In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. (CVE-2025-47827)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5066836
Risk Factor
High
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0824
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
6.2 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2016-9535
CVE CVE-2025-24052
CVE CVE-2025-24990
CVE CVE-2025-25004
CVE CVE-2025-47827
CVE CVE-2025-50152
CVE CVE-2025-53768
CVE CVE-2025-54957
CVE CVE-2025-55325
CVE CVE-2025-55328
CVE CVE-2025-55333
CVE CVE-2025-55335
CVE CVE-2025-55338
CVE CVE-2025-55678
CVE CVE-2025-55683
CVE CVE-2025-55687
CVE CVE-2025-55692
CVE CVE-2025-55695
CVE CVE-2025-55699
CVE CVE-2025-55700
CVE CVE-2025-55701
CVE CVE-2025-58714
CVE CVE-2025-58715
CVE CVE-2025-58716
CVE CVE-2025-58717
CVE CVE-2025-58718
CVE CVE-2025-58719
CVE CVE-2025-58722
CVE CVE-2025-58725
CVE CVE-2025-58726
CVE CVE-2025-58729
CVE CVE-2025-58730
CVE CVE-2025-58732
CVE CVE-2025-58733
CVE CVE-2025-58734
CVE CVE-2025-58735
CVE CVE-2025-58736
CVE CVE-2025-58737
CVE CVE-2025-58739
CVE CVE-2025-59184
CVE CVE-2025-59185
CVE CVE-2025-59186
CVE CVE-2025-59187
CVE CVE-2025-59188
CVE CVE-2025-59190
CVE CVE-2025-59192
CVE CVE-2025-59196
CVE CVE-2025-59197
CVE CVE-2025-59198
CVE CVE-2025-59200
CVE CVE-2025-59201
CVE CVE-2025-59202
CVE CVE-2025-59203
CVE CVE-2025-59205
CVE CVE-2025-59208
CVE CVE-2025-59209
CVE CVE-2025-59211
CVE CVE-2025-59214
CVE CVE-2025-59230
CVE CVE-2025-59242
CVE CVE-2025-59244
CVE CVE-2025-59253
CVE CVE-2025-59254
CVE CVE-2025-59258
CVE CVE-2025-59259
CVE CVE-2025-59260
CVE CVE-2025-59275
CVE CVE-2025-59277
CVE CVE-2025-59278
CVE CVE-2025-59280
CVE CVE-2025-59282
CVE CVE-2025-59294
CVE CVE-2025-59295
MSKB 5066836
XREF MSFT:MS25-5066836
XREF CISA-KNOWN-EXPLOITED:2025/11/04
XREF IAVA:2025-A-0775-S
XREF IAVA:2025-A-0776-S
Plugin Information
Published: 2025/10/14, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5066836

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8519
274780 - KB5068864: Windows 10 Version 1607 / Windows Server 2016 Security Update (November 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5068864. It is, therefore, affected by multiple vulnerabilities

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands.
(CVE-2025-60724, CVE-2025-60714, CVE-2025-60715, CVE-2025-62452)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-59505, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59512, CVE-2025-59514, CVE-2025-60703, CVE-2025-60704, CVE-2025-60705, CVE-2025-60709, CVE-2025-60713, CVE-2025-60719, CVE-2025-60720, CVE-2025-62213, CVE-2025-62217)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5068864
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/11/11, Modified: 2025/11/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5068864

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8592
66417 - MS13-042: Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397)
-
Synopsis
Microsoft Publisher, a component of Microsoft Office installed on the remote host is affected by multiple vulnerabilities.
Description
The Publisher component of Microsoft Office installed on the remote host is affected by multiple vulnerabilities :

- The application has a negative value allocation vulnerability. (CVE-2013-1316)

- The application has an integer overflow vulnerability.
(CVE-2013-1317)

- The application has a corrupt interface pointer vulnerability. (CVE-2013-1318)

- The application has a return value handling vulnerability. (CVE-2013-1319)

- The application has a buffer overflow vulnerability.
(CVE-2013-1320)

- The application has a return value validation vulnerability. (CVE-2013-1321)

- The application has an invalid range check vulnerability. (CVE-2013-1322)

- The application has an incorrect NULL value handling vulnerability. (CVE-2013-1323)

- The application has a signed integer vulnerability.
(CVE-2013-1327)

- The application has a pointer handling vulnerability.
(CVE-2013-1328)

- The application has a buffer underflow vulnerability.
(CVE-2013-1329)

A remote attacker could exploit these by tricking a user into opening a specially crafted Publisher file, resulting in remote code execution.
See Also
Solution
Microsoft has released a set of patches for Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1.
Risk Factor
Critical
VPR Score
6.7
EPSS Score
0.6476
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
BID 58771
BID 59761
BID 59762
BID 59763
BID 59764
BID 59766
BID 59767
BID 59768
BID 59769
BID 59770
BID 59772
CVE CVE-2013-1316
CVE CVE-2013-1317
CVE CVE-2013-1318
CVE CVE-2013-1319
CVE CVE-2013-1320
CVE CVE-2013-1321
CVE CVE-2013-1322
CVE CVE-2013-1323
CVE CVE-2013-1327
CVE CVE-2013-1328
CVE CVE-2013-1329
MSKB 2810047
MSKB 2597971
MSKB 2553147
XREF MSFT:MS13-042
Plugin Information
Published: 2013/05/15, Modified: 2019/11/27
Plugin Output

tcp/445/cifs



Product : Publisher 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Mspub.exe
Installed version : 14.0.6026.1000
Fixed version : 14.0.6137.5000
56998 - Microsoft Office Unsupported Version Detection
-
Synopsis
The remote host contains an unsupported version of Microsoft Office.
Description
According to its version, the installation of Microsoft Office on the remote Windows host is no longer supported.
Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft Office that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0503
Plugin Information
Published: 2011/12/02, Modified: 2024/03/22
Plugin Output

tcp/445/cifs


Installed product : Office 2010
End of support date : October 13, 2020
Supported versions : Office 2016, 2019, 2021 or Office 365
64784 - Microsoft SQL Server Unsupported Version Detection
-
Synopsis
An unsupported version of a database server is running on the remote host.
Description
According to its self-reported version number, the installation of Microsoft SQL Server on the remote host is no longer supported.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.
See Also
Solution
Upgrade to a version of Microsoft SQL Server that is currently supported.
Risk Factor
Critical
CVSS v3.0 Base Score
10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
References
XREF IAVA:0001-A-0560
Plugin Information
Published: 2013/02/21, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


The following unsupported installations of Microsoft SQL Server were
detected :

Installed version : 13.0.5026.0 Express Edition
Install path : C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn
Instance : SQLEXPRESS
Minimum supported version : 13.0.6300.2 (2016 SP3)
234624 - Oracle Java SE Multiple Vulnerabilities (April 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the April 2025 CPU advisory.

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (gstreamer)). Supported versions that are affected are Oracle Java SE: 8u441, 8u441-perf; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-47606)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u441; Oracle GraalVM Enterprise Edition: 20.3.17 and 21.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-54534)

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.14 and 21.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM for JDK executes to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM for JDK accessible data as well as unauthorized access to critical data or complete access to all Oracle GraalVM for JDK accessible data. (CVE-2025-23083)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0067
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/04/18, Modified: 2025/08/12
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.451 or greater
242293 - Oracle Java SE Multiple Vulnerabilities (July 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the July 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2024-40896)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. (CVE-2025-30749)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and 24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-50059)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2025 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0023
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/07/18, Modified: 2025/10/30
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.461 or greater
119612 - Security Updates for Microsoft .NET Framework (December 2018)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly. An attacker who successfully exploited this vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2018-8540)

- A denial of service vulnerability exists when .NET Framework improperly handles special web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework application. The update addresses the vulnerability by correcting how the .NET Framework web application handles web requests. (CVE-2018-8517)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1175
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8517
CVE CVE-2018-8540
MSKB 4470637
MSKB 4470493
MSKB 4470492
MSKB 4470491
MSKB 4470630
MSKB 4470639
MSKB 4470498
MSKB 4471323
MSKB 4471321
MSKB 4471327
MSKB 4471324
MSKB 4471329
MSKB 4470640
MSKB 4470641
MSKB 4470500
MSKB 4470502
MSKB 4470622
MSKB 4470623
MSKB 4470602
MSKB 4470629
MSKB 4470600
MSKB 4470601
MSKB 4470499
MSKB 4470638
XREF MSFT:MS18-4470637
XREF MSFT:MS18-4470493
XREF MSFT:MS18-4470492
XREF MSFT:MS18-4470491
XREF MSFT:MS18-4470630
XREF MSFT:MS18-4470639
XREF MSFT:MS18-4470498
XREF MSFT:MS18-4471323
XREF MSFT:MS18-4471321
XREF MSFT:MS18-4471327
XREF MSFT:MS18-4471324
XREF MSFT:MS18-4471329
XREF MSFT:MS18-4470640
XREF MSFT:MS18-4470641
XREF MSFT:MS18-4470500
XREF MSFT:MS18-4470502
XREF MSFT:MS18-4470622
XREF MSFT:MS18-4470623
XREF MSFT:MS18-4470602
XREF MSFT:MS18-4470629
XREF MSFT:MS18-4470600
XREF MSFT:MS18-4470601
XREF MSFT:MS18-4470499
XREF MSFT:MS18-4470638
Plugin Information
Published: 2018/12/13, Modified: 2019/11/01
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4471321

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.extensions.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3282.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4471321
132999 - Security Updates for Microsoft .NET Framework (January 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly. An attacker who successfully exploited this vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2020-0646)

- A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0605, CVE-2020-0606)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
9.1 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.9386
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-0605
CVE CVE-2020-0606
CVE CVE-2020-0646
MSKB 4532935
MSKB 4535101
MSKB 4535103
MSKB 4535102
MSKB 4535105
MSKB 4535104
MSKB 4532933
MSKB 4534271
MSKB 4532938
MSKB 4534306
MSKB 4534977
MSKB 4534976
MSKB 4532936
MSKB 4534276
MSKB 4534293
MSKB 4534979
MSKB 4534978
XREF MSFT:MS20-4532935
XREF MSFT:MS20-4535101
XREF MSFT:MS20-4535103
XREF MSFT:MS20-4535102
XREF MSFT:MS20-4535105
XREF MSFT:MS20-4535104
XREF MSFT:MS20-4532933
XREF MSFT:MS20-4534271
XREF MSFT:MS20-4532938
XREF MSFT:MS20-4534306
XREF MSFT:MS20-4534977
XREF MSFT:MS20-4534976
XREF MSFT:MS20-4532936
XREF MSFT:MS20-4534276
XREF MSFT:MS20-4534293
XREF MSFT:MS20-4534979
XREF MSFT:MS20-4534978
XREF IAVA:2020-A-0028-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
CANVAS (true) Metasploit (true)
Plugin Information
Published: 2020/01/16, Modified: 2023/04/25
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4534271

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.workflow.runtime.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3570.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4534271
117431 - Security Updates for Microsoft .NET Framework (September 2018)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. (CVE-2018-8421)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.4314
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105222
CVE CVE-2018-8421
MSKB 4457035
MSKB 4457038
MSKB 4457033
MSKB 4457142
MSKB 4457030
MSKB 4457025
MSKB 4457027
MSKB 4457026
MSKB 4457043
MSKB 4457028
MSKB 4457128
MSKB 4457045
MSKB 4457044
MSKB 4457132
MSKB 4457131
MSKB 4457036
MSKB 4457037
MSKB 4457034
MSKB 4457053
MSKB 4457054
MSKB 4457055
MSKB 4457056
MSKB 4457138
MSKB 4457029
MSKB 4457042
XREF MSFT:MS18-4457035
XREF MSFT:MS18-4457038
XREF MSFT:MS18-4457033
XREF MSFT:MS18-4457142
XREF MSFT:MS18-4457030
XREF MSFT:MS18-4457025
XREF MSFT:MS18-4457027
XREF MSFT:MS18-4457026
XREF MSFT:MS18-4457043
XREF MSFT:MS18-4457028
XREF MSFT:MS18-4457128
XREF MSFT:MS18-4457045
XREF MSFT:MS18-4457044
XREF MSFT:MS18-4457132
XREF MSFT:MS18-4457131
XREF MSFT:MS18-4457036
XREF MSFT:MS18-4457037
XREF MSFT:MS18-4457034
XREF MSFT:MS18-4457053
XREF MSFT:MS18-4457054
XREF MSFT:MS18-4457055
XREF MSFT:MS18-4457056
XREF MSFT:MS18-4457138
XREF MSFT:MS18-4457029
XREF MSFT:MS18-4457042
Plugin Information
Published: 2018/09/12, Modified: 2019/11/01
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4457131

C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.workflow.runtime.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3180.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4457131
207065 - Security Updates for Microsoft SQL Server Elevation of Privilege (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is affected by the following vulnerabilities:

- An elevation of privilege vulnerability. An authenticated, remote attacker can exploit this issue, to gain elevated privileges. (CVE-2024-37341, CVE-2024-37965, CVE-2024-37980)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Critical
CVSS v3.0 Base Score
9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.076
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-37341
CVE CVE-2024-37965
CVE CVE-2024-37980
MSKB 5042207
MSKB 5042209
MSKB 5042578
MSKB 5042749
MSKB 5042211
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042207
XREF MSFT:MS24-5042209
XREF MSFT:MS24-5042578
XREF MSFT:MS24-5042749
XREF MSFT:MS24-5042211
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2025/01/08
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER

156103 - Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104)
-
Synopsis
A package installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Apache Log4j on the remote host is 1.2. It is, therefore, affected by a remote code execution vulnerability when specifically configured to use JMSAppender.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.722
CVSS v2.0 Base Score
6.0 (CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-4104
XREF IAVA:2021-A-0573
XREF IAVA:0001-A-0650
Plugin Information
Published: 2021/12/15, Modified: 2024/06/13
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Fixed version : 2.16.0

tcp/0


Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Installed version : 1.2.17
Fixed version : 2.16.0

237498 - Apache Tomcat 9.0.0.M1 < 9.0.105
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.105. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.105_security-9 advisory.

- Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. (CVE-2025-46701)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.105 or later.
Risk Factor
Medium
CVSS v4.0 Base Score
6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
6.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.2
EPSS Score
0.0001
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-46701
XREF IAVA:2025-A-0389-S
Plugin Information
Published: 2025/05/29, Modified: 2025/08/12
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.105

237498 - Apache Tomcat 9.0.0.M1 < 9.0.105
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.105. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.105_security-9 advisory.

- Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. (CVE-2025-46701)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.105 or later.
Risk Factor
Medium
CVSS v4.0 Base Score
6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
6.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.2
EPSS Score
0.0001
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-46701
XREF IAVA:2025-A-0389-S
Plugin Information
Published: 2025/05/29, Modified: 2025/08/12
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.105

237498 - Apache Tomcat 9.0.0.M1 < 9.0.105
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.105. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.105_security-9 advisory.

- Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. (CVE-2025-46701)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.105 or later.
Risk Factor
Medium
CVSS v4.0 Base Score
6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
6.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.2
EPSS Score
0.0001
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-46701
XREF IAVA:2025-A-0389-S
Plugin Information
Published: 2025/05/29, Modified: 2025/08/12
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.105

240060 - Apache Tomcat 9.0.0.M1 < 9.0.106 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.106. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.106_security-9 advisory.

- Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49124)

- Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-55668)

- Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49125)

- Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-48988)

- Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. (CVE-2025-48976)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.106 or later.
Risk Factor
High
CVSS v4.0 Base Score
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48976
CVE CVE-2025-48988
CVE CVE-2025-49124
CVE CVE-2025-49125
CVE CVE-2025-55668
XREF IAVA:2025-A-0437-S
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/06/16, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.106

240060 - Apache Tomcat 9.0.0.M1 < 9.0.106 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.106. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.106_security-9 advisory.

- Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49124)

- Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-55668)

- Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49125)

- Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-48988)

- Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. (CVE-2025-48976)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.106 or later.
Risk Factor
High
CVSS v4.0 Base Score
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48976
CVE CVE-2025-48988
CVE CVE-2025-49124
CVE CVE-2025-49125
CVE CVE-2025-55668
XREF IAVA:2025-A-0437-S
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/06/16, Modified: 2025/08/15
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.106

240060 - Apache Tomcat 9.0.0.M1 < 9.0.106 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.106. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.106_security-9 advisory.

- Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49124)

- Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-55668)

- Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-49125)

- Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. (CVE-2025-48988)

- Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. (CVE-2025-48976)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.106 or later.
Risk Factor
High
CVSS v4.0 Base Score
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.6 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0002
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48976
CVE CVE-2025-48988
CVE CVE-2025-49124
CVE CVE-2025-49125
CVE CVE-2025-55668
XREF IAVA:2025-A-0437-S
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/06/16, Modified: 2025/08/15
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.106

241680 - Apache Tomcat 9.0.0.M1 < 9.0.107 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.107. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.107_security-9 advisory.

- The vulnerability exists due to overflow in file upload limit. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52520)

- The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests with APR/Native. A remote attacker can send specially crafted HTTP requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52434)

- The vulnerability exists due to application does not properly control consumption of internal resources when handling excessive HTTP/2 streams. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack. (CVE-2025-53506)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.107 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-52434
CVE CVE-2025-52520
CVE CVE-2025-53506
XREF IAVA:2025-A-0478
Plugin Information
Published: 2025/07/10, Modified: 2025/07/11
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.107

241680 - Apache Tomcat 9.0.0.M1 < 9.0.107 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.107. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.107_security-9 advisory.

- The vulnerability exists due to overflow in file upload limit. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52520)

- The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests with APR/Native. A remote attacker can send specially crafted HTTP requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52434)

- The vulnerability exists due to application does not properly control consumption of internal resources when handling excessive HTTP/2 streams. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack. (CVE-2025-53506)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.107 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-52434
CVE CVE-2025-52520
CVE CVE-2025-53506
XREF IAVA:2025-A-0478
Plugin Information
Published: 2025/07/10, Modified: 2025/07/11
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.107

241680 - Apache Tomcat 9.0.0.M1 < 9.0.107 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.107. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.107_security-9 advisory.

- The vulnerability exists due to overflow in file upload limit. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52520)

- The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests with APR/Native. A remote attacker can send specially crafted HTTP requests to the server and perform a denial of service (DoS) attack. (CVE-2025-52434)

- The vulnerability exists due to application does not properly control consumption of internal resources when handling excessive HTTP/2 streams. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack. (CVE-2025-53506)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.107 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-52434
CVE CVE-2025-52520
CVE CVE-2025-53506
XREF IAVA:2025-A-0478
Plugin Information
Published: 2025/07/10, Modified: 2025/07/11
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.107

249235 - Apache Tomcat 9.0.0.M1 < 9.0.108
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.108. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.108_security-9 advisory.

- Tomcat's HTTP/2 implementation was vulnerable to the made you reset attack. The denial of service typically manifested as an OutOfMemoryError. (CVE-2025-48989)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.108 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0004
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48989
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/08/14, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.108

249235 - Apache Tomcat 9.0.0.M1 < 9.0.108
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.108. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.108_security-9 advisory.

- Tomcat's HTTP/2 implementation was vulnerable to the made you reset attack. The denial of service typically manifested as an OutOfMemoryError. (CVE-2025-48989)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.108 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0004
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48989
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/08/14, Modified: 2025/08/15
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.108

249235 - Apache Tomcat 9.0.0.M1 < 9.0.108
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.108. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.108_security-9 advisory.

- Tomcat's HTTP/2 implementation was vulnerable to the made you reset attack. The denial of service typically manifested as an OutOfMemoryError. (CVE-2025-48989)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.108 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0004
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-48989
XREF IAVA:2025-A-0582
Plugin Information
Published: 2025/08/14, Modified: 2025/08/15
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.108

271694 - Apache Tomcat 9.0.0.M1 < 9.0.110
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.110. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.110_security-9 advisory.

- Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete.
Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.
(CVE-2025-61795)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.110 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0004
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-61795
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.110

271694 - Apache Tomcat 9.0.0.M1 < 9.0.110
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.110. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.110_security-9 advisory.

- Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete.
Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.
(CVE-2025-61795)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.110 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0004
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-61795
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/10/31
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.110

271694 - Apache Tomcat 9.0.0.M1 < 9.0.110
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.110. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.110_security-9 advisory.

- Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete.
Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.
(CVE-2025-61795)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.110 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0004
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-61795
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/10/31
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.110

201848 - Apache Tomcat 9.0.0.M1 < 9.0.90
-
Synopsis
The remote Apache Tomcat server is affected by a vulnerability
Description
The version of Tomcat installed on the remote host is prior to 9.0.90. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_9.0.90_security-9 advisory.

- Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue. (CVE-2024-34750)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.90 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.1724
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-34750
XREF IAVA:2024-A-0393-S
Plugin Information
Published: 2024/07/03, Modified: 2024/09/26
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.90
271691 - Apache Tomcat 9.0.0.M11 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55752)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0015
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55752
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/11/20
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.109

271691 - Apache Tomcat 9.0.0.M11 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55752)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0015
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55752
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/11/20
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.109

271691 - Apache Tomcat 9.0.0.M11 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55752)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0015
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55752
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/27, Modified: 2025/11/20
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.109

271806 - Apache Tomcat 9.0.40 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55754)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55754
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/28, Modified: 2025/11/20
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.109

271806 - Apache Tomcat 9.0.40 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55754)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55754
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/28, Modified: 2025/11/20
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Installed version : 9.0.104
Fixed version : 9.0.109

271806 - Apache Tomcat 9.0.40 < 9.0.109 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.109. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.109_security-9 advisory.

- Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected:
8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. (CVE-2025-55754)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.109 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.0002
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-55754
XREF IAVA:2025-A-0803
Plugin Information
Published: 2025/10/28, Modified: 2025/11/20
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Installed version : 9.0.104
Fixed version : 9.0.109

242116 - Apache Tomcat 9.0.76 < 9.0.104 multiple vulnerabilities
-
Synopsis
The remote Apache Tomcat server is affected by multiple vulnerabilities
Description
The version of Tomcat installed on the remote host is prior to 9.0.104. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.104_security-9 advisory.

- Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue. (CVE-2025-31650)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Apache Tomcat version 9.0.104 or later.
Risk Factor
High
CVSS v4.0 Base Score
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
VPR Score
4.4
EPSS Score
0.0003
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
STIG Severity
I
References
CVE CVE-2025-31650
XREF IAVA:2025-A-0369
Plugin Information
Published: 2025/07/15, Modified: 2025/07/15
Plugin Output

tcp/445/cifs


Path : D:\XTPL\Tomcat\
Installed version : 9.0.89
Fixed version : 9.0.104
110491 - KB4284880: Windows 10 Version 1607 and Windows Server 2016 June 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4284880.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-8169)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2018-8251)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2018-8205)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2018-8239)

- A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take control of the affected system. (CVE-2018-8231)

- An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2018-8234)

- A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. (CVE-2018-8226)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8229)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8267)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8207)

- An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-1036)

- A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. (CVE-2018-8225)

- A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins. The vulnerability allows Microsoft Edge to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the vulnerability could force the browser to send data that would otherwise be restricted. (CVE-2018-8235)

- An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user. An authenticated attacker who successfully exploited the vulnerability could access the Wireless LAN profile of an administrative user, including passwords for wireless networks. An attacker would need to log on to the affected system and run a specific command. The security update addresses the vulnerability by changing the way that Windows enforces access permissions to Wireless LAN profiles. (CVE-2018-8209)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-0978)

- An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels. An attacker who successfully exploited this vulnerability could gain elevated privileges on a target guest operating system. The host operating system is not vulnerable to this attack. This vulnerability by itself does not allow arbitrary code to be run. However, the vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running. The update addresses the vulnerability by correcting how privileges are enforced by Windows Hyper-V instruction emulation.
(CVE-2018-8219)

- A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the local machine.
(CVE-2018-8201, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221)

- A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8236)

- A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing. An attacker who successfully exploited the vulnerability could cause a system to stop responding. Note that the denial of service condition would not allow an attacker to execute code or to elevate user privileges. However, the denial of service condition could prevent authorized users from using system resources. An attacker could host a specially crafted file in a website or SMB share.
The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment. The security update addresses the vulnerability by modifying how the Code Integrity Module performs hashing.
(CVE-2018-1040)

- A remote code execution vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could take control of an affected system. (CVE-2018-8210, CVE-2018-8213)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions. An attacker who successfully exploited the vulnerability could impersonate processes, interject cross-process communication, or interrupt system functionality.
(CVE-2018-0982)

- An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8208, CVE-2018-8214)
See Also
Solution
Apply Cumulative Update KB4284880.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.8146
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.3 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 104328
BID 104331
BID 104333
BID 104334
BID 104336
BID 104337
BID 104338
BID 104340
BID 104343
BID 104353
BID 104356
BID 104360
BID 104361
BID 104364
BID 104369
BID 104373
BID 104379
BID 104382
BID 104389
BID 104391
BID 104392
BID 104393
BID 104394
BID 104395
BID 104398
BID 104401
BID 104404
BID 104406
BID 104407
CVE CVE-2018-0978
CVE CVE-2018-0982
CVE CVE-2018-1036
CVE CVE-2018-1040
CVE CVE-2018-8169
CVE CVE-2018-8201
CVE CVE-2018-8205
CVE CVE-2018-8207
CVE CVE-2018-8208
CVE CVE-2018-8209
CVE CVE-2018-8210
CVE CVE-2018-8212
CVE CVE-2018-8213
CVE CVE-2018-8214
CVE CVE-2018-8215
CVE CVE-2018-8216
CVE CVE-2018-8217
CVE CVE-2018-8219
CVE CVE-2018-8221
CVE CVE-2018-8225
CVE CVE-2018-8226
CVE CVE-2018-8229
CVE CVE-2018-8231
CVE CVE-2018-8234
CVE CVE-2018-8235
CVE CVE-2018-8236
CVE CVE-2018-8239
CVE CVE-2018-8251
CVE CVE-2018-8267
MSKB 4284880
XREF MSFT:MS18-4284880
Plugin Information
Published: 2018/06/12, Modified: 2024/09/20
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4284880

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2311
110980 - KB4338814: Windows 10 Version 1607 and Windows Server 2016 July 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4338814.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. (CVE-2018-8202)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8242, CVE-2018-8296)

- A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses. An attacker who successfully exploited the vulnerability could cause a system to stop responding. Note that the denial of service condition would not allow an attacker to execute code or to elevate user privileges. However, the denial of service condition could prevent authorized users from using system resources. (CVE-2018-8304)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2018-8309)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8280, CVE-2018-8290)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8282)

- A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8125, CVE-2018-8275)

- A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2018-8206)

- A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the local machine.
(CVE-2018-8222)

- A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources. An attacker who successfully exploited the vulnerability could force the browser to load data that would otherwise be restricted.
(CVE-2018-0949)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8308)

- A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects. An attacker who successfully exploited the vulnerability could bypass content blocking. In a file- sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince a user to open the document file. The security update addresses the vulnerability by correcting how Microsoft WordPad handles input. (CVE-2018-8307)

- A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8260)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions. An attacker who successfully exploited the vulnerability could impersonate processes, interject cross-process communication, or interrupt system functionality.
(CVE-2018-8313)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8287, CVE-2018-8288, CVE-2018-8291)

- A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly. An attacker who successfully exploited this vulnerability could take control of an affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2018-8284)

- A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates. An attacker could present expired certificates when challenged. The security update addresses the vulnerability by ensuring that .NET Framework components correctly validate certificates.
(CVE-2018-8356)
See Also
Solution
Apply Cumulative Update KB4338814.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.8368
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 104617
BID 104620
BID 104622
BID 104623
BID 104629
BID 104631
BID 104632
BID 104634
BID 104635
BID 104636
BID 104637
BID 104638
BID 104642
BID 104644
BID 104648
BID 104664
BID 104665
BID 104666
BID 104667
BID 104668
BID 104669
BID 104670
CVE CVE-2018-0949
CVE CVE-2018-8125
CVE CVE-2018-8202
CVE CVE-2018-8206
CVE CVE-2018-8222
CVE CVE-2018-8242
CVE CVE-2018-8260
CVE CVE-2018-8275
CVE CVE-2018-8280
CVE CVE-2018-8282
CVE CVE-2018-8284
CVE CVE-2018-8287
CVE CVE-2018-8288
CVE CVE-2018-8290
CVE CVE-2018-8291
CVE CVE-2018-8296
CVE CVE-2018-8304
CVE CVE-2018-8307
CVE CVE-2018-8308
CVE CVE-2018-8309
CVE CVE-2018-8313
CVE CVE-2018-8356
MSKB 4338814
XREF MSFT:MS18-4338814
Plugin Information
Published: 2018/07/10, Modified: 2024/09/05
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4338814

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2363
111685 - KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4343887.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8341, CVE-2018-8348)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8344)

- An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it. (CVE-2018-8343)

- A remote code execution vulnerability exists in &quot;Microsoft COM for Windows&quot; when it fails to properly handle serialized objects. An attacker who successfully exploited the vulnerability could use a specially crafted file or script to perform actions. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file.
(CVE-2018-8349)

- A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests. The vulnerability allows Microsoft Edge to bypass Cross- Origin Resource Sharing (CORS) redirect restrictions, and to follow redirect requests that should otherwise be ignored. An attacker who successfully exploited the vulnerability could force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice. (CVE-2018-8358)

- A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the local machine.
(CVE-2018-8200, CVE-2018-8204)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8355, CVE-2018-8372, CVE-2018-8385)

- An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links. An attacker who successfully exploited this vulnerability could potentially access privileged registry keys and thereby elevate permissions. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8347)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2018-8345)

- A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests. An attacker who has successfully exploited this vulnerability might be able to read privileged data across trust boundaries. In browsing scenarios, an attacker could convince a user to visit a malicious site and leverage the vulnerability to obtain privileged information from the browser process, such as sensitive data from other opened tabs. An attacker could also inject malicious code into advertising networks used by trusted sites or embed malicious code on a compromised, but trusted, site. The update addresses the vulnerability by correcting how the WebAudio Library handles audio requests. (CVE-2018-8370)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8404)

- An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. (CVE-2018-8339)

- A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests.
(CVE-2018-8340)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8266, CVE-2018-8381)

- An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen. An attacker who successfully exploited the vulnerability could steal browser stored passwords or log on to websites as another user. (CVE-2018-8253)

- A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-8316)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2018-8394, CVE-2018-8398)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8403)

- An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction. An attacker who successfully exploited this vulnerability could allow an attacker to obtain browser frame or window state from a different domain. For an attack to be successful, an attacker must persuade a user to open a malicious website from a secure website.
This update addresses the vulnerability by denying permission to read the state of the object model, to which frames or windows on different domains should not have access. (CVE-2018-8351)

- An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. (CVE-2018-8357)

- An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations. (CVE-2018-0952)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2018-8353, CVE-2018-8371, CVE-2018-8373, CVE-2018-8389)

- An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-8401, CVE-2018-8405, CVE-2018-8406)

- An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments. The vulnerability is caused when .NET Framework is used in high-load/high-density network connections where content from one stream can blend into another stream.
(CVE-2018-8360)

- A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content. An attacker who successfully exploited this vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
(CVE-2018-8388)
See Also
Solution
Apply Cumulative Update KB4343887 as well as refer to the KB article for additional information.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.8242
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 104977
BID 104978
BID 104980
BID 104982
BID 104983
BID 104984
BID 104986
BID 104987
BID 104988
BID 104992
BID 104995
BID 104999
BID 105001
BID 105006
BID 105007
BID 105008
BID 105009
BID 105011
BID 105012
BID 105017
BID 105027
BID 105029
BID 105030
BID 105048
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3646
CVE CVE-2018-0952
CVE CVE-2018-8200
CVE CVE-2018-8204
CVE CVE-2018-8253
CVE CVE-2018-8266
CVE CVE-2018-8316
CVE CVE-2018-8339
CVE CVE-2018-8340
CVE CVE-2018-8341
CVE CVE-2018-8343
CVE CVE-2018-8344
CVE CVE-2018-8345
CVE CVE-2018-8347
CVE CVE-2018-8348
CVE CVE-2018-8349
CVE CVE-2018-8351
CVE CVE-2018-8353
CVE CVE-2018-8355
CVE CVE-2018-8357
CVE CVE-2018-8358
CVE CVE-2018-8360
CVE CVE-2018-8370
CVE CVE-2018-8371
CVE CVE-2018-8372
CVE CVE-2018-8373
CVE CVE-2018-8381
CVE CVE-2018-8385
CVE CVE-2018-8388
CVE CVE-2018-8389
CVE CVE-2018-8394
CVE CVE-2018-8398
CVE CVE-2018-8401
CVE CVE-2018-8403
CVE CVE-2018-8404
CVE CVE-2018-8405
CVE CVE-2018-8406
MSKB 4343887
XREF MSFT:MS18-4343887
XREF CISA-KNOWN-EXPLOITED:2022/04/15
XREF CISA-KNOWN-EXPLOITED:2022/04/18
Exploitable With
Core Impact (true)
Plugin Information
Published: 2018/08/14, Modified: 2022/03/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4343887

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2430
117997 - KB4462917: Windows 10 Version 1607 and Windows Server 2016 October 2018 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4462917.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8460, CVE-2018-8491)

- A security feature bypass vulnerability exists in DNS Global Blocklist feature. An attacker who successfully exploited this vulnerability could redirect traffic to malicious DNS endpoints. The update addresses the vulnerability by updating DNS Server Role record additions to not bypass the Global Query Blocklist.
(CVE-2018-8320)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8330)

- An information disclosure vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how DirectX handles objects in memory.
(CVE-2018-8486)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. (CVE-2018-8472)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8453)

- An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2018-8493)

- An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-8411)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2018-8494)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2018-8489, CVE-2018-8490)

- A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the local machine.
(CVE-2018-8492)

- An information disclosure vulnerability exists when Windows Media Player improperly discloses file information. Successful exploitation of the vulnerability could allow an attacker to determine the presence of files on disk. (CVE-2018-8481, CVE-2018-8482)

- A remote code execution vulnerability exists when &quot;Windows Theme API&quot; does not properly decompress files. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2018-8413)

- A remote code execution vulnerability exists when Windows Shell improperly handles URIs. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8495)

- An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2018-8484)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2018-8503, CVE-2018-8505)

- A remote code execution vulnerability exists in the Microsoft JET Database Engine. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (CVE-2018-8423)

- An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute elevated code and take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8333)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2018-8497)
See Also
Solution
Apply Cumulative Update KB4462917.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.7816
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 105477
BID 105478
CVE CVE-2018-8320
CVE CVE-2018-8330
CVE CVE-2018-8333
CVE CVE-2018-8411
CVE CVE-2018-8413
CVE CVE-2018-8423
CVE CVE-2018-8453
CVE CVE-2018-8460
CVE CVE-2018-8472
CVE CVE-2018-8481
CVE CVE-2018-8482
CVE CVE-2018-8484
CVE CVE-2018-8486
CVE CVE-2018-8489
CVE CVE-2018-8490
CVE CVE-2018-8491
CVE CVE-2018-8492
CVE CVE-2018-8493
CVE CVE-2018-8494
CVE CVE-2018-8495
CVE CVE-2018-8497
CVE CVE-2018-8503
CVE CVE-2018-8505
MSKB 4462917
XREF MSFT:MS18-4462917
XREF CISA-KNOWN-EXPLOITED:2022/07/21
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2018/10/09, Modified: 2022/01/24
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4462917

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2551
121012 - KB4480961: Windows 10 Version 1607 and Windows Server 2016 January 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4480961. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0536, CVE-2019-0549, CVE-2019-0554)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0539, CVE-2019-0567)

- An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross- origin Resource Sharing (CORS) configurations. An attacker who successfully exploited the vulnerability could retrieve content, that is normally restricted, from a web application. The security update addresses the vulnerability by enforcing CORS configuration to prevent its bypass. (CVE-2019-0545)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0538, CVE-2019-0575, CVE-2019-0576, CVE-2019-0577, CVE-2019-0578, CVE-2019-0579, CVE-2019-0580, CVE-2019-0581, CVE-2019-0582, CVE-2019-0583, CVE-2019-0584)

- An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser.
An attacker who successfully exploited this vulnerability could gain elevated privileges and break out of the Edge AppContainer sandbox. The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running. The security update addresses the vulnerability by modifying how the Microsoft XmlDocument class enforces sandboxing.
(CVE-2019-0555)

- An elevation of privilege vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way Windows handles authentication requests. (CVE-2019-0543)

- An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
(CVE-2019-0570)

- A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input. An attacker could execute arbitrary code in the context of the current user. (CVE-2019-0541)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0551)

- An elevation of privilege exists in Windows COM Desktop Broker. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2019-0552)

- An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object. An attacker who successfully exploited the vulnerability could use the Browser Broker COM object to elevate privileges on an affected system. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. (CVE-2019-0566)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory. (CVE-2019-0569)

- An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Data Sharing Service handles file operations. (CVE-2019-0571, CVE-2019-0572, CVE-2019-0573, CVE-2019-0574)
See Also
Solution
Apply Cumulative Update KB4480961.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9097
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Plugin Information
Published: 2019/01/08, Modified: 2022/05/24
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4480961

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2724
119769 - KB4483229: Windows 10 Version 1607 and Windows Server 2016 December 2018 OOB Security Update
-
Synopsis
The remote Windows host is affected by a remote code execution vulnerability.
Description
The remote Windows host is missing security update 4483229.
It is, therefore, affected by a remote code execution vulnerability:

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8653)
See Also
Solution
Apply Cumulative Update KB4483229.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.2298
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2018-8653
MSKB 4483229
XREF MSFT:MS18-4483229
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Plugin Information
Published: 2018/12/19, Modified: 2025/03/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4483229

- C:\Windows\system32\pcadm.dll has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2670
122785 - KB4489882: Windows 10 Version 1607 and Windows Server 2016 March 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4489882.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0782)

- A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0779)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0780)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0609)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0702, CVE-2019-0755, CVE-2019-0775)

- An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests. An authenticated attacker who successfully exploited this vulnerability could craft a special packet, which could lead to information disclosure from the server. (CVE-2019-0703, CVE-2019-0704, CVE-2019-0821)

- An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory. An attacker who successfully exploited this vulnerability could use the information to further exploit the victim system. (CVE-2019-0759)

- An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. (CVE-2019-0678)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0617)

- A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. (CVE-2019-0690)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0797)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-0754)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2019-0695)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0680, CVE-2019-0783)

- A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0784)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0776)

- An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. (CVE-2019-0766)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0696)

- A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system.
(CVE-2019-0603)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-0614, CVE-2019-0774)

- An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
(CVE-2019-0767)

- A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0763)

- A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs. This could allow an attacker to cause a user to access a URL in a less restricted Internet Security Zone than intended.
(CVE-2019-0761)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0746)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2019-0756)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0665, CVE-2019-0666, CVE-2019-0667, CVE-2019-0772)

- A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0765)
See Also
Solution
Apply Cumulative Update KB4489882.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.4527
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Plugin Information
Published: 2019/03/12, Modified: 2022/05/25
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4489882

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2848
123943 - KB4493470: Windows 10 Version 1607 and Windows Server 2016 April 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4493470.
It is, therefore, affected by multiple vulnerabilities :

- A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys). An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine.
(CVE-2019-0732)

- An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a users system. (CVE-2019-0839)

- An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0688)

- A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions. An attacker who exploited the vulnerability could pass custom command line parameters.
(CVE-2019-0764)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-0730, CVE-2019-0731, CVE-2019-0805, CVE-2019-0836)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0752, CVE-2019-0753, CVE-2019-0862)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-0844)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-0802, CVE-2019-0849)

- A remote code execution vulnerability exists when OLE automation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could gain execution on the victim system.
(CVE-2019-0794)

- A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2019-0845)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0853)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0842)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0739)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879)

- An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0735)

- An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0838)

- A remote code execution vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could take control of an affected system. (CVE-2019-0856)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0814, CVE-2019-0848)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0685, CVE-2019-0803, CVE-2019-0859)

- A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the users system. (CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861)

- An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0835)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys). An attacker who successfully exploited this vulnerability could set the short name of a file with a long name to an arbitrary short name, overriding the file system with limited privileges. (CVE-2019-0796)
See Also
Solution
Apply Cumulative Update KB4493470.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.9207
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2019/04/09, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4493470

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.2906
125816 - KB4503267: Windows 10 Version 1607 and Windows Server 2016 June 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4503267.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-0943)

- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1051, CVE-2019-1052)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1014, CVE-2019-1017)

- A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. (CVE-2019-1040)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2019-0710, CVE-2019-0711, CVE-2019-0713)

- An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-0990, CVE-2019-1023)

- An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
(CVE-2019-0983)

- An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. (CVE-2019-0973)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-0904, CVE-2019-0905, CVE-2019-0906, CVE-2019-0907, CVE-2019-0908, CVE-2019-0909, CVE-2019-0974)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1018)

- An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity (XXE) declaration. (CVE-2019-0948)

- A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set the MOTW means that a large number of Microsoft security technologies are bypassed.
(CVE-2019-1054)

- A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1043)

- A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. (CVE-2019-1019)

- A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0920, CVE-2019-1005, CVE-2019-1055, CVE-2019-1080)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1038)

- An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1064)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-0620, CVE-2019-0709, CVE-2019-0722)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-1025)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-0988)

- An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. (CVE-2019-1007, CVE-2019-1028)

- An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
(CVE-2019-1039)

- This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic reboot of the system. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests. (CVE-2019-0972)

- An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1081)

- An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox.
(CVE-2019-1053)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-1010, CVE-2019-1012, CVE-2019-1046, CVE-2019-1050)

- A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim users privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory.
(CVE-2019-0888)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2019-0984)

- A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering. (CVE-2019-0941)

- An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. (CVE-2019-1069)

- An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. (CVE-2019-0986)
See Also
Solution
Apply Cumulative Update KB4503267.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.8977
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 108567
BID 108570
BID 108577
BID 108581
BID 108583
BID 108585
BID 108586
BID 108587
BID 108588
BID 108591
BID 108594
BID 108597
BID 108598
BID 108599
BID 108600
BID 108603
BID 108604
BID 108606
BID 108607
BID 108609
BID 108612
BID 108613
BID 108614
BID 108620
BID 108621
BID 108624
BID 108630
BID 108632
BID 108633
BID 108638
BID 108641
BID 108644
BID 108646
BID 108647
BID 108648
BID 108650
BID 108651
BID 108652
BID 108654
BID 108655
BID 108656
BID 108657
BID 108658
BID 108659
BID 108660
BID 108661
BID 108662
BID 108664
BID 108665
BID 108666
BID 108667
BID 108668
BID 108669
BID 108670
BID 108671
BID 108708
BID 108709
CVE CVE-2019-0620
CVE CVE-2019-0709
CVE CVE-2019-0710
CVE CVE-2019-0711
CVE CVE-2019-0713
CVE CVE-2019-0722
CVE CVE-2019-0888
CVE CVE-2019-0904
CVE CVE-2019-0905
CVE CVE-2019-0906
CVE CVE-2019-0907
CVE CVE-2019-0908
CVE CVE-2019-0909
CVE CVE-2019-0920
CVE CVE-2019-0941
CVE CVE-2019-0943
CVE CVE-2019-0948
CVE CVE-2019-0972
CVE CVE-2019-0973
CVE CVE-2019-0974
CVE CVE-2019-0983
CVE CVE-2019-0984
CVE CVE-2019-0986
CVE CVE-2019-0988
CVE CVE-2019-0989
CVE CVE-2019-0990
CVE CVE-2019-0991
CVE CVE-2019-0992
CVE CVE-2019-0993
CVE CVE-2019-1002
CVE CVE-2019-1003
CVE CVE-2019-1005
CVE CVE-2019-1007
CVE CVE-2019-1010
CVE CVE-2019-1012
CVE CVE-2019-1014
CVE CVE-2019-1017
CVE CVE-2019-1018
CVE CVE-2019-1019
CVE CVE-2019-1023
CVE CVE-2019-1025
CVE CVE-2019-1028
CVE CVE-2019-1038
CVE CVE-2019-1039
CVE CVE-2019-1040
CVE CVE-2019-1043
CVE CVE-2019-1046
CVE CVE-2019-1050
CVE CVE-2019-1051
CVE CVE-2019-1052
CVE CVE-2019-1053
CVE CVE-2019-1054
CVE CVE-2019-1055
CVE CVE-2019-1064
CVE CVE-2019-1069
CVE CVE-2019-1080
CVE CVE-2019-1081
MSKB 4503267
XREF MSFT:MS19-4503267
XREF CEA-ID:CEA-2020-0129
XREF CEA-ID:CEA-2019-0430
XREF CISA-KNOWN-EXPLOITED:2022/04/05
Exploitable With
Core Impact (true)
Plugin Information
Published: 2019/06/11, Modified: 2025/05/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4503267

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3024
128637 - KB4516044: Windows 10 Version 1607 and Windows Server 2016 September 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4516044.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives. An attacker who successfully exploited this vulnerability could inject commands or read input sent through a malicious Input Method Editor (IME). This only affects systems that have installed an IME. (CVE-2019-1235)

- An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks. An attacker who successfully exploited this vulnerability could potentially read data outside their expected limits. (CVE-2019-1282)

- An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1274)

- An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk. An attacker could exploit the vulnerability by reading a file to recover kernel memory. (CVE-2019-1254)

- An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions. An attacker who successfully exploited the vulnerability could overwrite files that require higher privileges than what the attacker already has. (CVE-2019-1289)

- An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations. An attacker who successfully exploited this vulnerability could write files to folders that require higher privileges than what the attacker already has. (CVE-2019-1142)

- An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
(CVE-2019-1244, CVE-2019-1245)

- An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files.
(CVE-2019-1270)

- An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1267)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1269, CVE-2019-1272)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2019-1280)

- An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could potentially disclose contents of System memory.
(CVE-2019-1293)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly impersonates file operations.
(CVE-2019-1232)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1256, CVE-2019-1285)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1208, CVE-2019-1236)

- An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2019-1287)

- A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1290, CVE-2019-1291)

- A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs. This could allow an attacker to cause a user to access a URL in a less restricted Internet Security Zone than intended.
(CVE-2019-1220)

- An elevation of privilege exists when Winlogon does not properly handle file path information. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1268)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2019-0928)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2019-1214)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-1252, CVE-2019-1286)

- An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2019-1278)

- An information disclosure vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how DirectX handles objects in memory.
(CVE-2019-1216)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2019-1292)

- An elevation of privilege exists in hdAudio.sys which may lead to an out of band write. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data.
(CVE-2019-1271)

- An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. (CVE-2019-1219)

- An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated privileges. (CVE-2019-1215)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2019-1221)
- A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1138, CVE-2019-1237, CVE-2019-1298, CVE-2019-1300)
See Also
Solution
Apply Cumulative Update KB4516044.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.4485
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2019/09/10, Modified: 2023/01/30
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4516044

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3204
131927 - KB4530689: Windows 10 Version 1607 and Windows Server 2016 December 2019 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4530689.
It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code. (CVE-2019-1484)

- A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding. (CVE-2019-1453)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2019-1472, CVE-2019-1474)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1468)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2019-1465, CVE-2019-1466, CVE-2019-1467)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2019-1469)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2019-1458)

- An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2019-1476)

- An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. (CVE-2019-1470)

- A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers.
An attacker could exploit the vulnerability to trigger warnings and false positives when no threat is present.
(CVE-2019-1488)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2019-1485)
See Also
Solution
Apply Cumulative Update KB4530689.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.922
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2019-1453
CVE CVE-2019-1458
CVE CVE-2019-1465
CVE CVE-2019-1466
CVE CVE-2019-1467
CVE CVE-2019-1468
CVE CVE-2019-1469
CVE CVE-2019-1470
CVE CVE-2019-1472
CVE CVE-2019-1474
CVE CVE-2019-1476
CVE CVE-2019-1484
CVE CVE-2019-1485
CVE CVE-2019-1488
MSKB 4530689
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF MSFT:MS19-4530689
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2019/12/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4530689

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3383
133611 - KB4537764: Windows 10 Version 1607 and Windows Server 2016 February 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4537764. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0670)

- A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0681, CVE-2020-0734, CVE-2020-0817)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-0738)

- An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests. An attacker who successfully exploited this vulnerability could determine the origin of all of the web pages in the affected browser. (CVE-2020-0706)

- An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to obtain information that could be used to try to further compromise the affected system. (CVE-2020-0658)

- An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-0737)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-0668)

- A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability can bypass secure boot and load untrusted software. (CVE-2020-0689)

- An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0742, CVE-2020-0743, CVE-2020-0749, CVE-2020-0750)

- An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-0739)

- An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory. (CVE-2020-0704)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0691)

- An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest. (CVE-2020-0665)

- An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. (CVE-2020-0753, CVE-2020-0754)

- An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Data Sharing Service handles file operations. (CVE-2020-0659, CVE-2020-0747)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. (CVE-2020-0661)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0716)

- A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. (CVE-2020-0662)

- An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files. (CVE-2020-0683, CVE-2020-0686)

- An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. (CVE-2020-0703)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2020-0729)

- An elevation of privilege vulnerability exists when the Windows IME improperly handles memory. (CVE-2020-0707)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0657)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731)

- An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
(CVE-2020-0727)

- An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. (CVE-2020-0730)

- An information vulnerability exists when Windows Modules Installer Service improperly discloses file information.
Successful exploitation of the vulnerability could allow the attacker to read any file on the file system.
(CVE-2020-0728)

- An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0679, CVE-2020-0680, CVE-2020-0682)

- An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory. (CVE-2020-0705)

- An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory. (CVE-2020-0675, CVE-2020-0676, CVE-2020-0677, CVE-2020-0748, CVE-2020-0755, CVE-2020-0756)

- A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding. (CVE-2020-0660)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. (CVE-2020-0744)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0709, CVE-2020-0732)

- A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an authenticated attacker abuses clipboard redirection. An attacker who successfully exploited this vulnerability could execute arbitrary code on the victim system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0655)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. (CVE-2020-0678)

- An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-0666, CVE-2020-0667, CVE-2020-0735, CVE-2020-0752)

- An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a users system. (CVE-2020-0698)

- An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0715, CVE-2020-0745)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2020-0673, CVE-2020-0674)

- A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.
(CVE-2020-0708)

- A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0710, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767)

- An elevation of privilege vulnerability exists in the way that the sysmain.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring the sysmain.dll properly handles objects in memory.
(CVE-2020-0818)
See Also
Solution
Apply Cumulative Update KB4537764.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9364
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/02/11, Modified: 2023/01/23
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4537764

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3503
135468 - KB4550929: Windows 10 Version 1607 and Windows Server 2016 April 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4550929.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to. (CVE-2020-0936)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0962)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-0948, CVE-2020-0949, CVE-2020-0950)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2020-0968)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0995, CVE-2020-0999, CVE-2020-1008)

- An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2020-0940, CVE-2020-1006, CVE-2020-1017)

- A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted image file. The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory. (CVE-2020-0965)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1000, CVE-2020-1003)

- An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory.
An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-0937, CVE-2020-0945, CVE-2020-0946)

- An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1009)

- A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi- master font - Adobe Type 1 PostScript format. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely.
For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as convincing a user to open a specially crafted document or viewing it in the Windows Preview pane. The update addresses the vulnerability by correcting how the Windows Adobe Type Manager Library handles Type1 fonts. (CVE-2020-0938, CVE-2020-1020)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1027)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-0821, CVE-2020-1007)

- An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Work Folder Service handles file operations. (CVE-2020-1094)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0964)

- An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0985)

- An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could overwrite files in arbitrary locations with elevated permissions. (CVE-2020-0942)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0687)

- An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. (CVE-2020-1014)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-0907)

- An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1004)

- An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1015)

- An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0983)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0956, CVE-2020-0958)

- An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0982, CVE-2020-0987, CVE-2020-1005)

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0784)

- An information disclosure vulnerability exists when the Windows Push Notification Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows Push Notification Service handles objects in memory.
(CVE-2020-1016)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-0895, CVE-2020-0966, CVE-2020-0967)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-0952)

- A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
(CVE-2020-0993)

- An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. (CVE-2020-0955)

- An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows System Assessment Tool handles file operations. (CVE-2020-1011)
- A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0969)
See Also
Solution
Apply Cumulative Update KB4550929.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.8931
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2020/04/14, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4550929

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3630
137258 - KB4561616: Windows 10 Version 1607 and Windows Server 2016 June 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4561616.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1196)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-1348)

- A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code. (CVE-2020-1281)

- An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1261, CVE-2020-1263)

- An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder. (CVE-2020-1255)

- An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1270)

- An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1291)

- An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. (CVE-2020-1302)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1202, CVE-2020-1203)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status. (CVE-2020-1197)

- An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. (CVE-2020-1271)

- An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1211)

- A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certain parameters. (CVE-2020-1241)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vulnerability by ensuring the Diagnostics Hub Standard Collector Service properly handles file operations. (CVE-2020-1257, CVE-2020-1278, CVE-2020-1293)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-1239)

- An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. (CVE-2020-1272)

- An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-1315)

- An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1287, CVE-2020-1294)

- A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files. (CVE-2020-1300)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1219)

- A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations. An attacker who successfully exploited the vulnerability could cause a denial of service against a system.
(CVE-2020-1194)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2020-1299)

- An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-1160)

- A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1073)

- An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows State Repository Service handles objects in memory.
(CVE-2020-1305)

- A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged. An attacker who successfully exploited the vulnerability could tamper with the log file. In an attack scenario, an attacker can change existing event log types to a type the parsers do not interpret allowing an attacker to append their own hash without triggering an alert. The update addresses the vulnerability by correcting how Windows Host Guardian Service handles logging of the measured boot hash.
(CVE-2020-1259)

- An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.
(CVE-2020-1309)

- A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server.
(CVE-2020-1301)

- An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
(CVE-2020-1231, CVE-2020-1235, CVE-2020-1282, CVE-2020-1304, CVE-2020-1334)

- An elevation of privilege vulnerability exists when an OLE Automation component improperly handles memory.
(CVE-2020-1212)

- An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1317)

- An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location. An attacker who successfully exploited the vulnerability could execute commands with elevated permissions. An authenticated attacker could modify a registry value to exploit this vulnerability. The security update addresses the vulnerability by ensuring that the spotlight images are always loaded from a secure location. (CVE-2020-1279)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1208, CVE-2020-1236)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0986, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1316)

- An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-0915, CVE-2020-0916)

- An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. The update addresses the vulnerability by correcting how Windows handles calls to preclude unintended elevation. (CVE-2020-1254)

- An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1311)

- An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310)

- A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. (CVE-2020-1283)

- An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles objects in memory. (CVE-2020-1234)

- A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects. An attacker who successfully exploits the IE Mode vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. (CVE-2020-1220)

- An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory.
An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1232)

- An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients.
An attacker who successfully exploited this vulnerability could run arbitrary code in a privileged process. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1314)
See Also
Solution
Apply Cumulative Update KB4561616.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.6162
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2020/06/09, Modified: 2023/03/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4561616

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3750
138458 - KB4565511: Windows 10 Version 1607 and Windows Server 2016 July 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4565511. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when the Windows System Events Broker improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1357)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1411)

- An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.
(CVE-2020-1352)

- An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1393)

- A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage. The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory. (CVE-2020-1409)

- An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory. An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. (CVE-2020-1385)

- An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1360)

- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1403)

- A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1374)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts. For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability:
(CVE-2020-1436)

- An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1368)

- An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1406)

- An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correcting how the Windows Graphics Component handles objects in memory. (CVE-2020-1351)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-1468)

- An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.
(CVE-2020-1365, CVE-2020-1371)

- An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1389, CVE-2020-1419)

- An elevation of privilege vulnerability exists in the way that the Windows Speech Brokered API handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1395)

- An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1344, CVE-2020-1362, CVE-2020-1369)

- An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory. (CVE-2020-1402)

- This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic reboot of the system. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests. (CVE-2020-1267)

- A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files. (CVE-2020-1410)

- An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1346)

- An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.
(CVE-2020-1354, CVE-2020-1430)

- An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1463)

- An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points. An attacker who successfully exploited this vulnerability could overwrite a targeted file that would normally require elevated permissions.
(CVE-2020-1333)

- An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based). An attacker who exploited the vulnerability could cause the user to place a call without additional consent, leading to information disclosure of the user profile. For the vulnerability to be exploited, a user must click a specially crafted URL that prompts the Skype app. (CVE-2020-1462)

- A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1408)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1336)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1396)

- A denial of service vulnerability exists in the way that the WalletService handles files. An attacker who successfully exploited the vulnerability could corrupt system files. (CVE-2020-1364)

- An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer. An attacker who exploited the vulnerability could cause the user to place a call without additional consent, leading to information disclosure of the user profile. For the vulnerability to be exploited, a user must click a specially crafted URL that prompts the Skype app.
(CVE-2020-1432)

- An elevation of privilege vulnerability exists in the way that the Windows Network Location Awareness Service handles objects in memory. An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. (CVE-2020-1437)

- A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. (CVE-2020-1147)

- An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1428, CVE-2020-1438)

- An elevation of privilege vulnerability exists when the Windows Cryptography Next Generation (CNG) Key Isolation service improperly handles memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1359, CVE-2020-1384)

- An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory. (CVE-2020-1358)

- An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1085)

- An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations. (CVE-2020-1420)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-1412)

- An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
(CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413)

- An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-1433)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1400, CVE-2020-1401, CVE-2020-1407)

- An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status. (CVE-2020-1429)

- An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1388)

- An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1356)

- A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. (CVE-2020-1421)

- An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system.
There are multiple ways an attacker could exploit this vulnerability: (CVE-2020-1397)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1435)

- An information disclosure vulnerability exists in the way that the WalletService handles memory.
(CVE-2020-1361)

- An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory. An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. (CVE-2020-1434)

- An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog. An attacker who successfully exploited the vulnerability could execute commands with elevated permissions. The security update addresses the vulnerability by ensuring that the Ease of Access dialog is handled properly. (CVE-2020-1398)
See Also
Solution
Apply Cumulative Update KB4565511.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.9343
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/07/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4565511

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3808
139488 - KB4571694: Windows 10 Version 1607 and Windows Server 2016 August 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4571694.
It is, therefore, affected by multiple vulnerabilities :

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-1379, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1525, CVE-2020-1554)

- A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects. (CVE-2020-1339)

- An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service handles file operations. (CVE-2020-1511)

- An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1475)

- An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory.
(CVE-2020-1549, CVE-2020-1550)

- An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
(CVE-2020-1577)

- An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly handles memory. (CVE-2020-1526)

- An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system (CVE-2020-1383)

- An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.
(CVE-2020-1470, CVE-2020-1484, CVE-2020-1516)

- An elevation of privilege vulnerability exists when the Windows Custom Protocol Engine improperly handles memory. (CVE-2020-1527)

- An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
(CVE-2020-1490)

- An elevation of privilege vulnerability exists when the Windows Speech Runtime improperly handles memory.
(CVE-2020-1521, CVE-2020-1522)

- An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.
(CVE-2020-1489, CVE-2020-1513)

- An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory.
(CVE-2020-1531)

- An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
(CVE-2020-1467)

- A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD Gateway service on the target system to stop responding.
(CVE-2020-1466)

- An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests. (CVE-2020-1509)

- A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory. An attacker who successfully exploited the vulnerability would gain execution on a victim system. The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory. (CVE-2020-1520)

- An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.
(CVE-2020-1519, CVE-2020-1538)

- An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows State Repository Service handles objects in memory. (CVE-2020-1512)

- An elevation of privilege vulnerability exists when the Windows Telephony Server improperly handles memory.
(CVE-2020-1515)

- An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory.
An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1487)

- An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1486, CVE-2020-1566)

- An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory. (CVE-2020-1517, CVE-2020-1518)

- An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1584)

- An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
(CVE-2020-1553)

- An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. (CVE-2020-1476)

- An elevation of privilege vulnerability exists when the Windows Remote Access improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-1537)

- An elevation of privilege vulnerability exists when the &quot;Public Account Pictures&quot; folder improperly handles junctions. (CVE-2020-1565)

- An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. (CVE-2020-1534)

- A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1568)

- An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. (CVE-2020-1472)

- An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit this vulnerability by running a specially crafted application. The security update addresses the vulnerability by helping to ensure that the Windows Kernel API properly handles objects in memory.
(CVE-2020-1377, CVE-2020-1378)

- An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1337)

- An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system.
(CVE-2020-1474, CVE-2020-1485)

- An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory. (CVE-2020-1587)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1473, CVE-2020-1557, CVE-2020-1558, CVE-2020-1564)

- A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. (CVE-2020-1046)

- An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1533, CVE-2020-1556)

- An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1529)

- A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
(CVE-2020-1380, CVE-2020-1570)

- An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. (CVE-2020-1488)

- An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. (CVE-2020-1579)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-1561, CVE-2020-1562)

- An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Work Folder Service handles file operations. (CVE-2020-1552)

- An elevation of privilege vulnerability exists when Windows Remote Access improperly handles memory.
(CVE-2020-1530)

- A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. (CVE-2020-1567)

- A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.
(CVE-2020-1464)
See Also
Solution
Apply Cumulative Update KB4571694.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
10.0
EPSS Score
0.9438
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1046
CVE CVE-2020-1337
CVE CVE-2020-1339
CVE CVE-2020-1377
CVE CVE-2020-1378
CVE CVE-2020-1379
CVE CVE-2020-1380
CVE CVE-2020-1383
CVE CVE-2020-1464
CVE CVE-2020-1466
CVE CVE-2020-1467
CVE CVE-2020-1470
CVE CVE-2020-1472
CVE CVE-2020-1473
CVE CVE-2020-1474
CVE CVE-2020-1475
CVE CVE-2020-1476
CVE CVE-2020-1477
CVE CVE-2020-1478
CVE CVE-2020-1484
CVE CVE-2020-1485
CVE CVE-2020-1486
CVE CVE-2020-1487
CVE CVE-2020-1488
CVE CVE-2020-1489
CVE CVE-2020-1490
CVE CVE-2020-1492
CVE CVE-2020-1509
CVE CVE-2020-1511
CVE CVE-2020-1512
CVE CVE-2020-1513
CVE CVE-2020-1515
CVE CVE-2020-1516
CVE CVE-2020-1517
CVE CVE-2020-1518
CVE CVE-2020-1519
CVE CVE-2020-1520
CVE CVE-2020-1521
CVE CVE-2020-1522
CVE CVE-2020-1525
CVE CVE-2020-1526
CVE CVE-2020-1527
CVE CVE-2020-1529
CVE CVE-2020-1530
CVE CVE-2020-1531
CVE CVE-2020-1533
CVE CVE-2020-1534
CVE CVE-2020-1537
CVE CVE-2020-1538
CVE CVE-2020-1549
CVE CVE-2020-1550
CVE CVE-2020-1552
CVE CVE-2020-1553
CVE CVE-2020-1554
CVE CVE-2020-1556
CVE CVE-2020-1557
CVE CVE-2020-1558
CVE CVE-2020-1561
CVE CVE-2020-1562
CVE CVE-2020-1564
CVE CVE-2020-1565
CVE CVE-2020-1566
CVE CVE-2020-1567
CVE CVE-2020-1568
CVE CVE-2020-1570
CVE CVE-2020-1577
CVE CVE-2020-1579
CVE CVE-2020-1584
CVE CVE-2020-1587
MSKB 4571694
XREF IAVA:0001-A-0647
XREF IAVA:2020-A-0361-S
XREF IAVA:2020-A-0367-S
XREF IAVA:2020-A-0370-S
XREF IAVA:2020-A-0438-S
XREF IAVA:2021-A-0429-S
XREF IAVA:2021-A-0431-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
XREF MSFT:MS20-4571694
XREF CISA-NCAS:AA22-011A
XREF CEA-ID:CEA-2021-0025
XREF CEA-ID:CEA-2021-0008
XREF CEA-ID:CEA-2020-0129
XREF CEA-ID:CEA-2020-0121
XREF CEA-ID:CEA-2020-0101
XREF CEA-ID:CEA-2023-0016
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/08/11, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4571694

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3866
140417 - KB4577015: Windows 10 Version 1607 and Windows Server 2016 September 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4577015.
It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-1053, CVE-2020-1308)

- An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory. (CVE-2020-0648)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1285)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory. (CVE-2020-1256)

- An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system (low- integrity to medium-integrity). This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls. (CVE-2020-0875)

- An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. (CVE-2020-1471)

- An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0921, CVE-2020-1083)

- A remote code execution vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account (CVE-2020-0718, CVE-2020-0761)

- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1245)

- An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-0839)

- A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects.
An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Audio Decoder handles objects. (CVE-2020-1508, CVE-2020-1593)

- An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-0886, CVE-2020-1559)

- An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a users system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document or by convincing a user to visit an untrusted webpage.
The update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
(CVE-2020-1091, CVE-2020-1097)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles file operations. (CVE-2020-1133)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-1039, CVE-2020-1074)

- A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
(CVE-2020-0836, CVE-2020-1228)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-1250)

- An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1052)

- An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows State Repository Service handles objects in memory. (CVE-2020-0914)

- An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1598)

- A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. Exploitation of the vulnerability requires that a program process a specially crafted image file. The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory. (CVE-2020-1129)

- An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-1030)

- An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. (CVE-2020-0912)

- A denial of service vulnerability exists when Windows Routing Utilities improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
(CVE-2020-1038)

- An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.
(CVE-2020-0766, CVE-2020-1146)

- A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls.. (CVE-2020-0790)

- An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog. (CVE-2020-0782)

- A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of the vulnerability requires that a program process a specially crafted image file. The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory. (CVE-2020-1319)

- An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory. (CVE-2020-1031)

- An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-1589, CVE-2020-16854)

- A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-0922)

- An information disclosure vulnerability exists when the win32k component improperly provides kernel information.
An attacker who successfully exploited the vulnerability could obtain information to further compromise the users system. (CVE-2020-0941)

- A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory.
An attacker who successfully exploited the vulnerability could gain execution on a victim system. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (Chromium-based), and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker- controlled content. Instead, an attacker would have to convince users to take action, typically by way of enticement in an email or Instant Messenger message, or by getting them to open an attachment sent through email. The security update addresses the vulnerability by correcting how the Windows Text Service Module handles memory. (CVE-2020-0908)

- A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel. (CVE-2020-1596)

- An elevation of privilege vulnerability exists in the way that fdSSDP.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1376)

- An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.
(CVE-2020-1152)

- A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2020-0997)

- An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
(CVE-2020-1034)

- An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-1115)

- A remote code execution vulnerability exists when Windows improperly handles objects in memory.
(CVE-2020-1252)

- A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-0878)

- A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC. (CVE-2020-0951)

- An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the vulnerability: (CVE-2020-1012)

- An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
(CVE-2020-1013)

- A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. (CVE-2020-1057, CVE-2020-1172, CVE-2020-1180)

- An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-1491)

- An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations. (CVE-2020-1130)

- An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Modules Installer handles objects in memory. (CVE-2020-0911)

- An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0838)

- An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target system.
(CVE-2020-0664, CVE-2020-0856)

- An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0998)

- A spoofing vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi- factor authentication requests. (CVE-2020-0837)

- An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-0870)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. (CVE-2020-0904)
See Also
Solution
Apply Cumulative Update KB4577015.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.3131
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2020/09/08, Modified: 2024/11/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4577015

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3930
141434 - KB4580346: Windows 10 Version 1607 and Windows Server 2016 October 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4580346.
It is, therefore, affected by multiple vulnerabilities :

- A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.
(CVE-2020-16922)

- A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. (CVE-2020-16924)

- A remote code execution vulnerability exists when Windows Network Address Translation (NAT) fails to properly handle UDP traffic. (CVE-2020-16894)

- An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-16885)

- A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. (CVE-2020-1167, CVE-2020-16923)

- A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. (CVE-2020-16891)

- An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-16892)

- An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability.
(CVE-2020-16914)

- An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. (CVE-2020-16902)

- An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-0764)

- An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-16896)

- A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2020-16911)

- An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-16897)

- An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. (CVE-2020-16876, CVE-2020-16920)

- A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. (CVE-2020-16915)

- An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. (CVE-2020-16940)

- A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. (CVE-2020-16910)

- An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. (CVE-2020-16939)

- An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. (CVE-2020-16905, CVE-2020-16909)

- A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. (CVE-2020-1243)

- A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding. (CVE-2020-16927)

- An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. (CVE-2020-16887)

- An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. (CVE-2020-16912, CVE-2020-16936, CVE-2020-16972, CVE-2020-16973, CVE-2020-16974, CVE-2020-16975, CVE-2020-16976)

- An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
(CVE-2020-16937)

- An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. (CVE-2020-16889)

- An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
(CVE-2020-16980)

- An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
(CVE-2020-16916, CVE-2020-16935)

- An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory. (CVE-2020-16900)

- An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability.
The security update addresses the vulnerability by ensuring the Windows Enterprise App Management Service properly handles file operations. (CVE-2020-16919)
See Also
Solution
Apply Cumulative Update KB4580346.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2221
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2020/10/13, Modified: 2024/11/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4580346

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.3986
143569 - KB4593226: Windows 10 Version 1607 and Windows Server 2016 December 2020 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 4593226.
It is, therefore, affected by multiple vulnerabilities:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2020-16958, CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964, CVE-2020-17092, CVE-2020-17097)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2020-17095, CVE-2020-17096)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2020-16996, CVE-2020-17099)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2020-17098, CVE-2020-17138, CVE-2020-17140)
See Also
Solution
Apply Cumulative Update KB4586830.
Risk Factor
High
CVSS v3.0 Base Score
8.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.1971
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16958
CVE CVE-2020-16959
CVE CVE-2020-16960
CVE CVE-2020-16961
CVE CVE-2020-16962
CVE CVE-2020-16963
CVE CVE-2020-16964
CVE CVE-2020-16996
CVE CVE-2020-17092
CVE CVE-2020-17095
CVE CVE-2020-17096
CVE CVE-2020-17097
CVE CVE-2020-17098
CVE CVE-2020-17099
CVE CVE-2020-17138
CVE CVE-2020-17140
MSKB 4593226
XREF MSFT:MS20-4593226
XREF IAVA:2020-A-0561-S
XREF IAVA:2020-A-0562-S
XREF CEA-ID:CEA-2020-0138
Plugin Information
Published: 2020/12/08, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 4593226

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4104
147222 - KB5000803: Windows Security Update (March 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5000803.
It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-24107, CVE-2021-26869, CVE-2021-26884)

- An memory corruption vulnerability exists. An attacker can exploit this to corrupt the memory and cause unexpected behaviors within the system/application.
(CVE-2021-26411)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-1640, CVE-2021-26862, CVE-2021-26864, CVE-2021-26865, CVE-2021-26866, CVE-2021-26868, CVE-2021-26872, CVE-2021-26873, CVE-2021-26875, CVE-2021-26878, CVE-2021-26880, CVE-2021-26882, CVE-2021-26891, CVE-2021-26898, CVE-2021-26899, CVE-2021-26901, CVE-2021-27077)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-26861, CVE-2021-26877, CVE-2021-26881, CVE-2021-26893, CVE-2021-26894, CVE-2021-26895, CVE-2021-26897)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-26879, CVE-2021-26886, CVE-2021-26896, CVE-2021-27063)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-26892)
See Also
Solution
Apply Cumulative Update KB5000803.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9247
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1640
CVE CVE-2021-24107
CVE CVE-2021-26411
CVE CVE-2021-26861
CVE CVE-2021-26862
CVE CVE-2021-26864
CVE CVE-2021-26865
CVE CVE-2021-26866
CVE CVE-2021-26868
CVE CVE-2021-26869
CVE CVE-2021-26872
CVE CVE-2021-26873
CVE CVE-2021-26875
CVE CVE-2021-26877
CVE CVE-2021-26878
CVE CVE-2021-26879
CVE CVE-2021-26880
CVE CVE-2021-26881
CVE CVE-2021-26882
CVE CVE-2021-26884
CVE CVE-2021-26886
CVE CVE-2021-26891
CVE CVE-2021-26892
CVE CVE-2021-26893
CVE CVE-2021-26894
CVE CVE-2021-26895
CVE CVE-2021-26896
CVE CVE-2021-26897
CVE CVE-2021-26898
CVE CVE-2021-26899
CVE CVE-2021-26901
CVE CVE-2021-27063
CVE CVE-2021-27077
MSKB 5000803
XREF MSFT:MS21-5000803
XREF IAVA:2021-A-0129-S
XREF IAVA:2021-A-0130-S
XREF IAVA:2021-A-0134-S
XREF IAVA:2021-A-0131-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
XREF CEA-ID:CEA-2021-0015
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2021/03/09, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5000803

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4283
148465 - KB5001347: Windows 10 version 1607 / Windows Server 2016 Security Update (Apr 2021)
-
Synopsis
The remote host is missing one or more security updates.
Description
The remote Windows host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Win32k Elevation of Privilege Vulnerability (CVE-2021-27072)

- Windows Media Photo Codec Information Disclosure Vulnerability (CVE-2021-27079)

- Microsoft Internet Messaging API Remote Code Execution Vulnerability (CVE-2021-27089)

- Windows Kernel Information Disclosure Vulnerability (CVE-2021-27093, CVE-2021-28309)

- Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability (CVE-2021-27094, CVE-2021-28447)

- Windows Media Video Decoder Remote Code Execution Vulnerability (CVE-2021-27095, CVE-2021-28315)

- NTFS Elevation of Privilege Vulnerability (CVE-2021-27096)

- Windows Installer Spoofing Vulnerability (CVE-2021-26413)

- Windows Installer Elevation of Privilege Vulnerability (CVE-2021-26415, CVE-2021-28440)

- Windows Hyper-V Denial of Service Vulnerability (CVE-2021-26416)

- Windows Application Compatibility Cache Denial of Service Vulnerability (CVE-2021-28311)

- Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability (CVE-2021-28316)

- Microsoft Windows Codecs Library Information Disclosure Vulnerability (CVE-2021-28317)

- Windows GDI+ Information Disclosure Vulnerability (CVE-2021-28318)

- Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability (CVE-2021-28320)

- Windows DNS Information Disclosure Vulnerability (CVE-2021-28323, CVE-2021-28328)

- Windows SMB Information Disclosure Vulnerability (CVE-2021-28325)

- Windows AppX Deployment Server Denial of Service Vulnerability (CVE-2021-28326)

- Remote Procedure Call Runtime Remote Code Execution Vulnerability (CVE-2021-28327, CVE-2021-28329, CVE-2021-28330, CVE-2021-28331, CVE-2021-28332, CVE-2021-28333, CVE-2021-28334, CVE-2021-28335, CVE-2021-28336, CVE-2021-28337, CVE-2021-28338, CVE-2021-28339, CVE-2021-28340, CVE-2021-28341, CVE-2021-28342, CVE-2021-28343, CVE-2021-28344, CVE-2021-28345, CVE-2021-28346, CVE-2021-28352, CVE-2021-28353, CVE-2021-28354, CVE-2021-28355, CVE-2021-28356, CVE-2021-28357, CVE-2021-28358, CVE-2021-28434)

- Windows Speech Runtime Elevation of Privilege Vulnerability (CVE-2021-28347, CVE-2021-28351, CVE-2021-28436)

- Windows GDI+ Remote Code Execution Vulnerability (CVE-2021-28348, CVE-2021-28349, CVE-2021-28350)

- Windows Event Tracing Information Disclosure Vulnerability (CVE-2021-28435)

- Windows Installer Information Disclosure Vulnerability (CVE-2021-28437)

- Windows TCP/IP Driver Denial of Service Vulnerability (CVE-2021-28439)

- Windows Console Driver Denial of Service Vulnerability (CVE-2021-28443)

- Windows Hyper-V Security Feature Bypass Vulnerability (CVE-2021-28444)

- N/A (CVE-2021-28445, CVE-2021-28446)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5001347 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.186
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2021/04/13, Modified: 2024/11/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5001347

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4350
150367 - KB5003638: Windows 10 version 1607 / Windows Server 2016 Security Update (June 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5003638. It is, therefore, affected by multiple vulnerabilities
See Also
Solution
Apply Cumulative Update 5003638
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9431
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1675
CVE CVE-2021-26414
CVE CVE-2021-31199
CVE CVE-2021-31201
CVE CVE-2021-31953
CVE CVE-2021-31954
CVE CVE-2021-31956
CVE CVE-2021-31958
CVE CVE-2021-31959
CVE CVE-2021-31962
CVE CVE-2021-31968
CVE CVE-2021-31970
CVE CVE-2021-31971
CVE CVE-2021-31972
CVE CVE-2021-31973
CVE CVE-2021-31974
CVE CVE-2021-31975
CVE CVE-2021-31976
CVE CVE-2021-31977
CVE CVE-2021-33742
MSKB 5003638
XREF MSFT:MS21-5003638
XREF IAVA:2021-A-0280-S
XREF IAVA:2021-A-0279-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
XREF CEA-ID:CEA-2021-0032
Exploitable With
Core Impact (true)
Plugin Information
Published: 2021/06/08, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5003638

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4467
151474 - KB5004948: Windows 10 1607 and Windows Server 2016 OOB Security Update RCE (July 2021)
-
Synopsis
The remote Windows host is affected by a remote code execution vulnerability.
Description
A remote command execution vulnerability exists in Windows Print Spooler service improperly performs privileged file operations. An authenticated, remote attacker can exploit this to bypass and run arbitrary code with SYSTEM privileges.
See Also
Solution
Apply Cumulative Update 5004948
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9427
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-34527
MSKB 5004948
XREF IAVA:2021-A-0299
XREF MSFT:MS21-5004948
XREF CEA-ID:CEA-2021-0034
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2021/07/08, Modified: 2025/12/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5004948

- C:\Windows\system32\localspl.dll has not been patched.
Remote version : 10.0.14393.2097
Should be : 10.0.14393.4470
153377 - KB5005573: Windows 10 Version 1607 and Windows Server 2016 September 2021 Security Update
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5005573.
It is, therefore, affected by multiple vulnerabilities :

- An memory corruption vulnerability exists. An attacker can exploit this to corrupt the memory and cause unexpected behaviors within the system/application.
(CVE-2021-26435)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-36960, CVE-2021-36962, CVE-2021-36969, CVE-2021-36972, CVE-2021-38629, CVE-2021-38635, CVE-2021-38636)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-38624, CVE-2021-38632)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-36955, CVE-2021-36963, CVE-2021-36964, CVE-2021-36967, CVE-2021-36973, CVE-2021-36974, CVE-2021-38628, CVE-2021-38630, CVE-2021-38633, CVE-2021-38634, CVE-2021-38638, CVE-2021-38639, CVE-2021-38667, CVE-2021-38671, CVE-2021-40447)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-36965, CVE-2021-36958, CVE-2021-40444)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-36961)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2021-36959)
See Also
Solution
Apply Cumulative Update KB5005573.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9433
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2021/09/14, Modified: 2024/11/28
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5005573

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4651
154034 - KB5006669: Windows 10 Version 1607 and Windows Server 2016 Security Update (October 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5006669.
It is, therefore, affected by multiple vulnerabilities:

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-36953, CVE-2021-40463)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-26441, CVE-2021-26442, CVE-2021-40443, CVE-2021-40449, CVE-2021-40466, CVE-2021-40467, CVE-2021-40470, CVE-2021-40476, CVE-2021-40477, CVE-2021-40478, CVE-2021-40488, CVE-2021-40489, CVE-2021-41335, CVE-2021-41345, CVE-2021-41347)

- A session spoofing vulnerability exists. An attacker can exploit this to perform actions with the privileges of another user. (CVE-2021-36970, CVE-2021-40455, CVE-2021-41361)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-40465, CVE-2021-40469, CVE-2021-41331, CVE-2021-41340, CVE-2021-41342)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-38662, CVE-2021-38663, CVE-2021-40454, CVE-2021-41332, CVE-2021-41343)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2021-40460, CVE-2021-41337, CVE-2021-41338)
Solution
Apply Security Update 5006669
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.9189
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.3 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2021/10/12, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5006669

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4704
154990 - KB5007192: Windows 10 Version 1607 and Windows Server 2016 Security Update (November 2021)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5007192.
It is, therefore, affected by multiple vulnerabilities:

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2021-38631, CVE-2021-38665, CVE-2021-41371)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-38666, CVE-2021-42275, CVE-2021-42276, CVE-2021-42279)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2021-41356, CVE-2021-42274, CVE-2021-42284)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2021-36957, CVE-2021-41366, CVE-2021-41367, CVE-2021-41370, CVE-2021-41377, CVE-2021-41379, CVE-2021-42277, CVE-2021-42278, CVE-2021-42280, CVE-2021-42282, CVE-2021-42283, CVE-2021-42285, CVE-2021-42287, CVE-2021-42291)
See Also
Solution
Apply Cumulative Update KB5007192.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.9407
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.3 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-36957
CVE CVE-2021-38631
CVE CVE-2021-38665
CVE CVE-2021-38666
CVE CVE-2021-41356
CVE CVE-2021-41366
CVE CVE-2021-41367
CVE CVE-2021-41370
CVE CVE-2021-41371
CVE CVE-2021-41377
CVE CVE-2021-41379
CVE CVE-2021-42274
CVE CVE-2021-42275
CVE CVE-2021-42276
CVE CVE-2021-42277
CVE CVE-2021-42278
CVE CVE-2021-42279
CVE CVE-2021-42280
CVE CVE-2021-42282
CVE CVE-2021-42283
CVE CVE-2021-42284
CVE CVE-2021-42285
CVE CVE-2021-42287
CVE CVE-2021-42291
MSKB 5007192
XREF MSFT:MS21-5007192
XREF IAVA:2021-A-0539-S
XREF IAVA:2021-A-0545-S
XREF CISA-KNOWN-EXPLOITED:2022/03/17
XREF CISA-KNOWN-EXPLOITED:2022/05/02
XREF CEA-ID:CEA-2021-0053
Plugin Information
Published: 2021/11/09, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5007192

- C:\Windows\system32\gdiplus.dll has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4770
157436 - KB5010359: Windows 10 Version 1607 and Windows Server 2016 Security Update (February 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5010359. It is, therefore, affected by multiple vulnerabilities

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-21993, CVE-2022-21998)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-22002)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21995)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2022-21989, CVE-2022-21997, CVE-2022-21999, CVE-2022-22000, CVE-2022-22001)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5010359
Risk Factor
High
CVSS v3.0 Base Score
7.9 (CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.6 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.7009
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21974
CVE CVE-2022-21981
CVE CVE-2022-21985
CVE CVE-2022-21989
CVE CVE-2022-21992
CVE CVE-2022-21993
CVE CVE-2022-21995
CVE CVE-2022-21997
CVE CVE-2022-21998
CVE CVE-2022-21999
CVE CVE-2022-22000
CVE CVE-2022-22001
CVE CVE-2022-22002
CVE CVE-2022-22710
CVE CVE-2022-22717
CVE CVE-2022-22718
MSKB 5010359
XREF MSFT:MS22-5010359
XREF IAVA:2022-A-0074-S
XREF IAVA:2022-A-0068-S
XREF CISA-KNOWN-EXPLOITED:2022/04/15
XREF CISA-KNOWN-EXPLOITED:2022/05/10
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2022/02/08, Modified: 2025/05/14
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5010359

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4946
158704 - KB5011495: Windows 10 Version 1607 and Windows Server 2016 Security Update (March 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5011495. It is, therefore, affected by multiple vulnerabilities

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2022-23283, CVE-2022-23284, CVE-2022-23287, CVE-2022-23290, CVE-2022-23293, CVE-2022-23296, CVE-2022-23298, CVE-2022-23299, CVE-2022-24454, CVE-2022-24455, CVE-2022-24459, CVE-2022-24460, CVE-2022-24505, CVE-2022-24507)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-21975, CVE-2022-23253)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-24502)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-21977, CVE-2022-22010, CVE-2022-23281, CVE-2022-23297, CVE-2022-24503)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-21990, CVE-2022-23285, CVE-2022-23294)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5011495.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.3021
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2022/03/08, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5011495

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5006
160934 - KB5013952: Windows 10 Version 1607 and Windows Server 2016 Security Update (May 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5013952. It is, therefore, affected by multiple vulnerabilities

- Windows LDAP Remote Code Execution Vulnerability (CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141)

- Windows Network File System Remote Code Execution Vulnerability (CVE-2022-26937)

- Active Directory Domain Services Elevation of Privilege Vulnerability (CVE-2022-26923)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5013952
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9144
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/05/10, Modified: 2025/01/07
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5013952

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5125
162196 - KB5014702: Windows 10 Version 1607 and Windows Server 2016 Security Update (June 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5014702. It is, therefore, affected by multiple vulnerabilities

- Windows Network File System Remote Code Execution Vulnerability (CVE-2022-30136)

- Windows Kerberos Elevation of Privilege Vulnerability (CVE-2022-30165)

- Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability (CVE-2022-30139, CVE-2022-30141, CVE-2022-30143, CVE-2022-30146, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5014702
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9361
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-21123
CVE CVE-2022-21125
CVE CVE-2022-21127
CVE CVE-2022-21166
CVE CVE-2022-30131
CVE CVE-2022-30136
CVE CVE-2022-30139
CVE CVE-2022-30140
CVE CVE-2022-30141
CVE CVE-2022-30142
CVE CVE-2022-30143
CVE CVE-2022-30145
CVE CVE-2022-30146
CVE CVE-2022-30147
CVE CVE-2022-30148
CVE CVE-2022-30149
CVE CVE-2022-30150
CVE CVE-2022-30151
CVE CVE-2022-30152
CVE CVE-2022-30153
CVE CVE-2022-30154
CVE CVE-2022-30155
CVE CVE-2022-30160
CVE CVE-2022-30161
CVE CVE-2022-30162
CVE CVE-2022-30163
CVE CVE-2022-30164
CVE CVE-2022-30165
CVE CVE-2022-30166
CVE CVE-2022-30190
MSKB 5014702
XREF MSFT:MS22-5014702
XREF IAVA:2022-A-0240-S
XREF IAVA:2022-A-0241-S
XREF CISA-KNOWN-EXPLOITED:2022/07/05
XREF CEA-ID:CEA-2022-0022
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2022/06/14, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5014702

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5192
163052 - KB5015808: Windows 10 Version 1607 and Windows Server 2016 Security Update (July 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5015808.
It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-22024, CVE-2022-22027, CVE-2022-22029, CVE-2022-22038, CVE-2022-22039, CVE-2022-30211, CVE-2022-30214, CVE-2022-30221, CVE-2022-30222)

- A security feature bypass vulnerability exists. An attacker can exploit this and bypass the security feature and perform unauthorized actions compromising the integrity of the system/application.
(CVE-2022-22023, CVE-2022-22048, CVE-2022-30203)

- A denial of service (DoS) vulnerability. An attacker can exploit this issue to cause the affected component to deny system or application services. (CVE-2022-22025, CVE-2022-22040, CVE-2022-22043, CVE-2022-30208)

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2022-22022, CVE-2022-22026, CVE-2022-22031, CVE-2022-22034, CVE-2022-22036, CVE-2022-22037, CVE-2022-22041, CVE-2022-22045, CVE-2022-22047, CVE-2022-22049, CVE-2022-22050, CVE-2022-30202, CVE-2022-30205, CVE-2022-30206, CVE-2022-30209, CVE-2022-30215, CVE-2022-30220, CVE-2022-30224, CVE-2022-30225, CVE-2022-30226)

- An information disclosure vulnerability. An attacker can exploit this to disclose potentially sensitive information. (CVE-2022-21845, CVE-2022-22028, CVE-2022-22042, CVE-2022-22711, CVE-2022-30213, CVE-2022-30223)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5015808
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.4674
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2022/07/12, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5015808

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5246
166039 - KB5018411: Windows 10 Version 1607 and Windows Server 2016 Security Update (October 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5018411. It is, therefore, affected by multiple vulnerabilities

- Server Service Remote Protocol Elevation of Privilege Vulnerability (CVE-2022-38045)

- Microsoft ODBC Driver Remote Code Execution Vulnerability (CVE-2022-38040)

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2022-37982, CVE-2022-38031)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5018411
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.246
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2022/10/11, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5018411

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5427
167111 - KB5019964: Windows 10 Version 1607 and Windows Server 2016 Security Update (November 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5019964. It is, therefore, affected by multiple vulnerabilities

- AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions (CVE-2022-23824)

- Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability (CVE-2022-37966)

- Windows Kerberos Elevation of Privilege Vulnerability (CVE-2022-37967)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5019964
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.3924
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-23824
CVE CVE-2022-37966
CVE CVE-2022-37967
CVE CVE-2022-37992
CVE CVE-2022-38015
CVE CVE-2022-38023
CVE CVE-2022-41039
CVE CVE-2022-41045
CVE CVE-2022-41047
CVE CVE-2022-41048
CVE CVE-2022-41049
CVE CVE-2022-41050
CVE CVE-2022-41052
CVE CVE-2022-41053
CVE CVE-2022-41054
CVE CVE-2022-41056
CVE CVE-2022-41057
CVE CVE-2022-41058
CVE CVE-2022-41064
CVE CVE-2022-41073
CVE CVE-2022-41086
CVE CVE-2022-41088
CVE CVE-2022-41090
CVE CVE-2022-41091
CVE CVE-2022-41093
CVE CVE-2022-41095
CVE CVE-2022-41097
CVE CVE-2022-41098
CVE CVE-2022-41099
CVE CVE-2022-41100
CVE CVE-2022-41101
CVE CVE-2022-41102
CVE CVE-2022-41109
CVE CVE-2022-41118
CVE CVE-2022-41125
CVE CVE-2022-41128
MSKB 5019964
XREF MSFT:MS22-5019964
XREF CISA-KNOWN-EXPLOITED:2022/12/09
XREF IAVA:2022-A-0477-S
XREF IAVA:2022-A-0484-S
XREF IAVA:2022-A-0473-S
XREF IAVA:2023-A-0552-S
XREF IAVA:2023-A-0553-S
Plugin Information
Published: 2022/11/08, Modified: 2025/10/22
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5019964

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5501
168694 - KB5021235: Windows 10 Version 1607 and Windows Server 2016 Security Update (December 2022)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5021235. It is, therefore, affected by multiple vulnerabilities

- PowerShell Remote Code Execution Vulnerability (CVE-2022-41076)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-44670, CVE-2022-44676)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5021235
Risk Factor
High
CVSS v3.0 Base Score
8.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.1 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.6798
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-41074
CVE CVE-2022-41076
CVE CVE-2022-41077
CVE CVE-2022-41094
CVE CVE-2022-41121
CVE CVE-2022-44666
CVE CVE-2022-44667
CVE CVE-2022-44668
CVE CVE-2022-44670
CVE CVE-2022-44673
CVE CVE-2022-44675
CVE CVE-2022-44676
CVE CVE-2022-44678
CVE CVE-2022-44679
CVE CVE-2022-44680
CVE CVE-2022-44681
CVE CVE-2022-44682
CVE CVE-2022-44683
CVE CVE-2022-44697
CVE CVE-2022-44698
CVE CVE-2022-44707
MSKB 5021235
XREF MSFT:MS22-5021235
XREF CISA-KNOWN-EXPLOITED:2023/01/03
XREF IAVA:2022-A-0530-S
XREF IAVA:2022-A-0533-S
Plugin Information
Published: 2022/12/13, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5021235

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5582
169779 - KB5022289: Windows 10 Version 1607 and Windows Server 2016 Security Update (January 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5022289. It is, therefore, affected by multiple vulnerabilities

- Microsoft ODBC Driver Remote Code Execution Vulnerability (CVE-2023-21732)

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-21681)

- Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (CVE-2023-21674)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5022289
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.5296
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/01/10, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5022289

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.5648
181312 - KB5030213: Windows 10 Version 1607 and Windows Server 2016 Security Update (September 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5030213. It is, therefore, affected by multiple vulnerabilities

- DHCP Server Service Denial of Service Vulnerability (CVE-2023-38162)

- Windows GDI Elevation of Privilege Vulnerability (CVE-2023-36804, CVE-2023-38161)

- DHCP Server Service Information Disclosure Vulnerability (CVE-2023-36801, CVE-2023-38152)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5030213
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0689
CVSS v2.0 Base Score
8.3 (CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36801
CVE CVE-2023-36803
CVE CVE-2023-36804
CVE CVE-2023-36805
CVE CVE-2023-38139
CVE CVE-2023-38140
CVE CVE-2023-38141
CVE CVE-2023-38142
CVE CVE-2023-38143
CVE CVE-2023-38144
CVE CVE-2023-38147
CVE CVE-2023-38149
CVE CVE-2023-38152
CVE CVE-2023-38160
CVE CVE-2023-38161
CVE CVE-2023-38162
MSKB 5030213
XREF MSFT:MS23-5030213
XREF IAVA:2023-A-0472-S
XREF IAVA:2023-A-0471-S
Plugin Information
Published: 2023/09/12, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5030213

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6252
186791 - KB5033373: Windows 10 Version 1607 and Windows Server 2016 Security Update (December 2023)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5033373. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2023-36006)

- Win32k Elevation of Privilege Vulnerability (CVE-2023-36011)

- A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. (CVE-2023-20588)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5033373
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.3857
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2023/12/12, Modified: 2025/10/31
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5033373

- C:\Windows\system32\pcadm.dll has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6529
187800 - KB5034119: Windows 10 Version 1607 and Windows Server 2016 Security Update (January 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5034119. It is, therefore, affected by multiple vulnerabilities

- Microsoft ODBC Driver Remote Code Execution Vulnerability (CVE-2024-20654)

- BitLocker Security Feature Bypass Vulnerability (CVE-2024-20666)

- Windows Kerberos Security Feature Bypass Vulnerability (CVE-2024-20674)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5034119
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.9 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2225
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.8 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/01/09, Modified: 2024/08/07
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5034119

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6611
190487 - KB5034767: Windows 10 Version 1607 and Windows Server 2016 Security Update (February 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5034767. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2024-21350, CVE-2024-21352, CVE-2024-21358, CVE-2024-21359, CVE-2024-21360, CVE-2024-21361, CVE-2024-21365, CVE-2024-21366, CVE-2024-21367, CVE-2024-21368, CVE-2024-21369, CVE-2024-21370, CVE-2024-21375, CVE-2024-21391, CVE-2024-21420)

- Windows Kernel Information Disclosure Vulnerability (CVE-2024-21340)

- Microsoft ActiveX Data Objects Remote Code Execution Vulnerability (CVE-2024-21349)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5034767
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.4613
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/02/13, Modified: 2024/06/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5034767

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6707
191934 - KB5035855: Windows 10 Version 1607 / Windows Server 2016 Security Update (March 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5035855. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161, CVE-2024-26166)

- Windows USB Hub Driver Remote Code Execution Vulnerability (CVE-2024-21429)

- Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability (CVE-2024-21430)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5035855
Risk Factor
Critical
CVSS v3.0 Base Score
8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.3458
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/03/12, Modified: 2025/10/22
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5035855

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6795
193097 - KB5036899: Windows 10 Version 1607 / Windows Server 2016 Security Update (April 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5036899. It is, therefore, affected by multiple vulnerabilities

- Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability (CVE-2024-26214)

- Secure Boot Security Feature Bypass Vulnerability (CVE-2024-20669, CVE-2024-26168, CVE-2024-26171, CVE-2024-26175, CVE-2024-26180, CVE-2024-26189, CVE-2024-26194, CVE-2024-26240, CVE-2024-26250, CVE-2024-28896, CVE-2024-28897, CVE-2024-28898, CVE-2024-28903, CVE-2024-28919, CVE-2024-28921, CVE-2024-28922, CVE-2024-28923, CVE-2024-28924, CVE-2024-28925, CVE-2024-29061, CVE-2024-29062)

- Windows rndismp6.sys Remote Code Execution Vulnerability (CVE-2024-26252, CVE-2024-26253)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5036899
Risk Factor
Critical
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.6
EPSS Score
0.8317
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/04/09, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5036899

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6897
197009 - KB5037763: Windows 10 Version 1607 / Windows Server 2016 Security Update (May 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5037763. It is, therefore, affected by multiple vulnerabilities

- Windows MSHTML Platform Security Feature Bypass Vulnerability (CVE-2024-30040)

- Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2024-29996, CVE-2024-30025, CVE-2024-30037)

- Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability (CVE-2024-30006)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5037763
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.2
EPSS Score
0.5191
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2024/05/14, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5037763

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.6981
200351 - KB5039214: Windows 10 Version 1607 / Windows Server 2016 Security Update (June 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5039214. It is, therefore, affected by multiple vulnerabilities

- Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability (CVE-2024-30097)

- Windows Remote Access Connection Manager Information Disclosure Vulnerability (CVE-2024-30069)

- DHCP Server Service Denial of Service Vulnerability (CVE-2024-30070)

- Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability (CVE-2024-30080)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5039214
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.8897
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-50868
CVE CVE-2024-30062
CVE CVE-2024-30063
CVE CVE-2024-30065
CVE CVE-2024-30066
CVE CVE-2024-30067
CVE CVE-2024-30068
CVE CVE-2024-30069
CVE CVE-2024-30070
CVE CVE-2024-30076
CVE CVE-2024-30077
CVE CVE-2024-30078
CVE CVE-2024-30080
CVE CVE-2024-30082
CVE CVE-2024-30083
CVE CVE-2024-30084
CVE CVE-2024-30086
CVE CVE-2024-30087
CVE CVE-2024-30088
CVE CVE-2024-30090
CVE CVE-2024-30091
CVE CVE-2024-30093
CVE CVE-2024-30094
CVE CVE-2024-30095
CVE CVE-2024-30097
CVE CVE-2024-30099
CVE CVE-2024-35250
CVE CVE-2024-38213
MSKB 5039214
XREF MSFT:MS24-5039214
XREF IAVA:2024-A-0343-S
XREF IAVA:2024-A-0345-S
XREF CISA-KNOWN-EXPLOITED:2025/01/06
XREF CISA-KNOWN-EXPLOITED:2024/11/05
XREF CISA-KNOWN-EXPLOITED:2024/09/03
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2024/06/11, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5039214

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7070
212232 - KB5048671: Windows 10 Version 1607 / Windows Server 2016 Security Update (December 2024)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5048671. It is, therefore, affected by multiple vulnerabilities

- Input Method Editor (IME) Remote Code Execution Vulnerability (CVE-2024-49079)

- Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2024-49090)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5048671
Risk Factor
Critical
CVSS v3.0 Base Score
8.4 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.0 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.8871
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2024/12/10, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5048671

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7604
214123 - KB5049993: Windows 10 Version 1607 / Windows Server 2016 Security Update (January 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5049993. It is, therefore, affected by multiple vulnerabilities

- Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVE-2025-21307)

- Windows Telephony Service Remote Code Execution Vulnerability (CVE-2025-21223, CVE-2025-21233, CVE-2025-21236, CVE-2025-21237, CVE-2025-21238, CVE-2025-21239, CVE-2025-21240, CVE-2025-21241, CVE-2025-21243, CVE-2025-21244, CVE-2025-21245, CVE-2025-21246, CVE-2025-21248, CVE-2025-21250, CVE-2025-21252, CVE-2025-21266, CVE-2025-21273, CVE-2025-21282, CVE-2025-21286, CVE-2025-21302, CVE-2025-21303, CVE-2025-21305, CVE-2025-21306, CVE-2025-21339, CVE-2025-21409, CVE-2025-21411, CVE-2025-21413, CVE-2025-21417)

- Windows BitLocker Information Disclosure Vulnerability (CVE-2025-21210, CVE-2025-21214)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5049993
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.7811
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-7344
CVE CVE-2025-21189
CVE CVE-2025-21193
CVE CVE-2025-21202
CVE CVE-2025-21210
CVE CVE-2025-21211
CVE CVE-2025-21213
CVE CVE-2025-21214
CVE CVE-2025-21215
CVE CVE-2025-21217
CVE CVE-2025-21218
CVE CVE-2025-21219
CVE CVE-2025-21220
CVE CVE-2025-21223
CVE CVE-2025-21225
CVE CVE-2025-21226
CVE CVE-2025-21227
CVE CVE-2025-21228
CVE CVE-2025-21229
CVE CVE-2025-21230
CVE CVE-2025-21231
CVE CVE-2025-21232
CVE CVE-2025-21233
CVE CVE-2025-21236
CVE CVE-2025-21237
CVE CVE-2025-21238
CVE CVE-2025-21239
CVE CVE-2025-21240
CVE CVE-2025-21241
CVE CVE-2025-21242
CVE CVE-2025-21243
CVE CVE-2025-21244
CVE CVE-2025-21245
CVE CVE-2025-21246
CVE CVE-2025-21248
CVE CVE-2025-21249
CVE CVE-2025-21250
CVE CVE-2025-21251
CVE CVE-2025-21252
CVE CVE-2025-21255
CVE CVE-2025-21256
CVE CVE-2025-21257
CVE CVE-2025-21258
CVE CVE-2025-21260
CVE CVE-2025-21261
CVE CVE-2025-21263
CVE CVE-2025-21265
CVE CVE-2025-21266
CVE CVE-2025-21268
CVE CVE-2025-21269
CVE CVE-2025-21270
CVE CVE-2025-21272
CVE CVE-2025-21273
CVE CVE-2025-21274
CVE CVE-2025-21276
CVE CVE-2025-21277
CVE CVE-2025-21278
CVE CVE-2025-21280
CVE CVE-2025-21281
CVE CVE-2025-21282
CVE CVE-2025-21284
CVE CVE-2025-21285
CVE CVE-2025-21286
CVE CVE-2025-21287
CVE CVE-2025-21288
CVE CVE-2025-21289
CVE CVE-2025-21290
CVE CVE-2025-21293
CVE CVE-2025-21294
CVE CVE-2025-21295
CVE CVE-2025-21296
CVE CVE-2025-21297
CVE CVE-2025-21298
CVE CVE-2025-21299
CVE CVE-2025-21300
CVE CVE-2025-21301
CVE CVE-2025-21302
CVE CVE-2025-21303
CVE CVE-2025-21304
CVE CVE-2025-21305
CVE CVE-2025-21306
CVE CVE-2025-21307
CVE CVE-2025-21308
CVE CVE-2025-21309
CVE CVE-2025-21310
CVE CVE-2025-21312
CVE CVE-2025-21314
CVE CVE-2025-21316
CVE CVE-2025-21318
CVE CVE-2025-21319
CVE CVE-2025-21320
CVE CVE-2025-21321
CVE CVE-2025-21323
CVE CVE-2025-21324
CVE CVE-2025-21327
CVE CVE-2025-21328
CVE CVE-2025-21329
CVE CVE-2025-21331
CVE CVE-2025-21332
CVE CVE-2025-21336
CVE CVE-2025-21338
CVE CVE-2025-21339
CVE CVE-2025-21341
CVE CVE-2025-21374
CVE CVE-2025-21378
CVE CVE-2025-21389
CVE CVE-2025-21409
CVE CVE-2025-21411
CVE CVE-2025-21413
CVE CVE-2025-21417
MSKB 5049993
XREF MSFT:MS25-5049993
XREF IAVA:2025-A-0034-S
XREF IAVA:2025-A-0033-S
XREF CWE:20
XREF CWE:41
XREF CWE:59
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:200
XREF CWE:203
XREF CWE:269
XREF CWE:284
XREF CWE:347
XREF CWE:352
XREF CWE:362
XREF CWE:400
XREF CWE:416
XREF CWE:451
XREF CWE:476
XREF CWE:532
XREF CWE:591
XREF CWE:636
XREF CWE:693
XREF CWE:843
XREF CWE:908
XREF CWE:922
Exploitable With
Metasploit (true)
Plugin Information
Published: 2025/01/14, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5049993

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7693
216134 - KB5052006: Windows 10 Version 1607 / Windows Server 2016 Security Update (February 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5052006. It is, therefore, affected by multiple vulnerabilities

- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2025-21208, CVE-2025-21410)

- Windows Telephony Service Remote Code Execution Vulnerability (CVE-2025-21190, CVE-2025-21200, CVE-2025-21371, CVE-2025-21406, CVE-2025-21407)

- Microsoft Digest Authentication Remote Code Execution Vulnerability (CVE-2025-21368, CVE-2025-21369)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5052006
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.2857
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
Exploitable With
Core Impact (true)
Plugin Information
Published: 2025/02/11, Modified: 2025/10/06
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5052006

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7783
232612 - KB5053594: Windows 10 Version 1607 / Windows Server 2016 Security Update (March 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5053594. It is, therefore, affected by multiple vulnerabilities

- Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. (CVE-2025-26645)

- Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. (CVE-2025-24035, CVE-2025-24045)

- ** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record's reference information. (CVE-2024-9157)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5053594
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.5654
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-9157
CVE CVE-2025-21180
CVE CVE-2025-21247
CVE CVE-2025-24035
CVE CVE-2025-24044
CVE CVE-2025-24045
CVE CVE-2025-24046
CVE CVE-2025-24048
CVE CVE-2025-24050
CVE CVE-2025-24051
CVE CVE-2025-24054
CVE CVE-2025-24055
CVE CVE-2025-24056
CVE CVE-2025-24059
CVE CVE-2025-24061
CVE CVE-2025-24064
CVE CVE-2025-24066
CVE CVE-2025-24067
CVE CVE-2025-24071
CVE CVE-2025-24072
CVE CVE-2025-24983
CVE CVE-2025-24984
CVE CVE-2025-24985
CVE CVE-2025-24987
CVE CVE-2025-24988
CVE CVE-2025-24991
CVE CVE-2025-24992
CVE CVE-2025-24993
CVE CVE-2025-24995
CVE CVE-2025-24996
CVE CVE-2025-25008
CVE CVE-2025-26633
CVE CVE-2025-26645
MSKB 5053594
XREF MSFT:MS25-5053594
XREF IAVA:2025-A-0181-S
XREF IAVA:2025-A-0182-S
XREF CISA-KNOWN-EXPLOITED:2025/05/08
XREF CISA-KNOWN-EXPLOITED:2025/04/01
XREF CWE:23
XREF CWE:41
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:200
XREF CWE:284
XREF CWE:416
XREF CWE:532
XREF CWE:591
XREF CWE:681
XREF CWE:693
XREF CWE:707
Plugin Information
Published: 2025/03/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5053594

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7870
234044 - KB5055521: Windows 10 Version 1607 / Windows Server 2016 Security Update (April 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5055521. It is, therefore, affected by multiple vulnerabilities

- Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. (CVE-2025-26687)

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-27481)
- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges. (CVE-2025-27740)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5055521
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.2827
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-21174
CVE CVE-2025-21191
CVE CVE-2025-21197
CVE CVE-2025-21203
CVE CVE-2025-21204
CVE CVE-2025-21205
CVE CVE-2025-21221
CVE CVE-2025-21222
CVE CVE-2025-24073
CVE CVE-2025-26637
CVE CVE-2025-26641
CVE CVE-2025-26647
CVE CVE-2025-26648
CVE CVE-2025-26652
CVE CVE-2025-26663
CVE CVE-2025-26664
CVE CVE-2025-26665
CVE CVE-2025-26667
CVE CVE-2025-26668
CVE CVE-2025-26669
CVE CVE-2025-26670
CVE CVE-2025-26671
CVE CVE-2025-26672
CVE CVE-2025-26673
CVE CVE-2025-26676
CVE CVE-2025-26679
CVE CVE-2025-26680
CVE CVE-2025-26686
CVE CVE-2025-26687
CVE CVE-2025-26688
CVE CVE-2025-27469
CVE CVE-2025-27470
CVE CVE-2025-27471
CVE CVE-2025-27473
CVE CVE-2025-27474
CVE CVE-2025-27477
CVE CVE-2025-27478
CVE CVE-2025-27479
CVE CVE-2025-27480
CVE CVE-2025-27481
CVE CVE-2025-27482
CVE CVE-2025-27483
CVE CVE-2025-27484
CVE CVE-2025-27485
CVE CVE-2025-27486
CVE CVE-2025-27487
CVE CVE-2025-27491
CVE CVE-2025-27727
CVE CVE-2025-27732
CVE CVE-2025-27733
CVE CVE-2025-27735
CVE CVE-2025-27736
CVE CVE-2025-27737
CVE CVE-2025-27738
CVE CVE-2025-27740
CVE CVE-2025-27741
CVE CVE-2025-27742
CVE CVE-2025-29809
CVE CVE-2025-29810
CVE CVE-2025-29824
MSKB 5055521
XREF CISA-KNOWN-EXPLOITED:2025/04/29
XREF MSFT:MS25-5055521
XREF IAVA:2025-A-0256-S
XREF IAVA:2025-A-0255-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:200
XREF CWE:284
XREF CWE:345
XREF CWE:367
XREF CWE:400
XREF CWE:410
XREF CWE:416
XREF CWE:591
XREF CWE:667
XREF CWE:693
XREF CWE:787
XREF CWE:908
XREF CWE:922
XREF CWE:1390
Plugin Information
Published: 2025/04/08, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5055521

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.7962
235842 - KB5058383: Windows 10 Version 1607 / Windows Server 2016 Security Update (May 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5058383. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. (CVE-2025-29967)

- Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29830, CVE-2025-29958, CVE-2025-29959)

- Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-29832, CVE-2025-29835, CVE-2025-29836, CVE-2025-29960, CVE-2025-29961)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5058383
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.2127
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-24063
CVE CVE-2025-26677
CVE CVE-2025-27468
CVE CVE-2025-29829
CVE CVE-2025-29830
CVE CVE-2025-29831
CVE CVE-2025-29832
CVE CVE-2025-29833
CVE CVE-2025-29835
CVE CVE-2025-29836
CVE CVE-2025-29837
CVE CVE-2025-29839
CVE CVE-2025-29840
CVE CVE-2025-29842
CVE CVE-2025-29954
CVE CVE-2025-29956
CVE CVE-2025-29957
CVE CVE-2025-29958
CVE CVE-2025-29959
CVE CVE-2025-29960
CVE CVE-2025-29961
CVE CVE-2025-29962
CVE CVE-2025-29966
CVE CVE-2025-29967
CVE CVE-2025-29968
CVE CVE-2025-29969
CVE CVE-2025-29974
CVE CVE-2025-30385
CVE CVE-2025-30388
CVE CVE-2025-30394
CVE CVE-2025-30397
CVE CVE-2025-32701
CVE CVE-2025-32706
CVE CVE-2025-32707
CVE CVE-2025-32709
CVE CVE-2025-32710
CVE CVE-2025-55229
MSKB 5058383
XREF MSFT:MS25-5058383
XREF CISA-KNOWN-EXPLOITED:2025/06/03
XREF IAVA:2025-A-0631-S
XREF IAVA:2025-A-0335-S
XREF IAVA:2025-A-0334-S
XREF CWE:20
XREF CWE:59
XREF CWE:121
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:191
XREF CWE:269
XREF CWE:345
XREF CWE:347
XREF CWE:349
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:770
XREF CWE:787
XREF CWE:843
XREF CWE:908
Plugin Information
Published: 2025/05/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5058383

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8062
238092 - KB5061010: Windows 10 Version 1607 / Windows Server 2016 Security Update (June 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5061010. It is, therefore, affected by multiple vulnerabilities

- Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-33066)

- Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
(CVE-2025-33073)

- Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
(CVE-2025-32712)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5061010
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.5119
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.7 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-3052
CVE CVE-2025-24065
CVE CVE-2025-24068
CVE CVE-2025-24069
CVE CVE-2025-32712
CVE CVE-2025-32713
CVE CVE-2025-32714
CVE CVE-2025-32715
CVE CVE-2025-32716
CVE CVE-2025-32718
CVE CVE-2025-32719
CVE CVE-2025-32720
CVE CVE-2025-32721
CVE CVE-2025-32722
CVE CVE-2025-32724
CVE CVE-2025-32725
CVE CVE-2025-33050
CVE CVE-2025-33053
CVE CVE-2025-33055
CVE CVE-2025-33056
CVE CVE-2025-33057
CVE CVE-2025-33058
CVE CVE-2025-33059
CVE CVE-2025-33060
CVE CVE-2025-33061
CVE CVE-2025-33062
CVE CVE-2025-33064
CVE CVE-2025-33065
CVE CVE-2025-33066
CVE CVE-2025-33067
CVE CVE-2025-33068
CVE CVE-2025-33070
CVE CVE-2025-33071
CVE CVE-2025-33073
CVE CVE-2025-33075
CVE CVE-2025-47160
MSKB 5061010
XREF MSFT:MS25-5061010
XREF IAVA:2025-A-0428-S
XREF IAVA:2025-A-0417-S
XREF CISA-KNOWN-EXPLOITED:2025/11/10
XREF CISA-KNOWN-EXPLOITED:2025/07/01
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:269
XREF CWE:284
XREF CWE:400
XREF CWE:416
XREF CWE:476
XREF CWE:693
XREF CWE:908
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2025/06/10, Modified: 2025/10/21
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5061010

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8146
241559 - KB5062560: Windows 10 Version 1607 / Windows Server 2016 Security Update (July 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5062560. It is, therefore, affected by multiple vulnerabilities

- Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
(CVE-2025-49659)

- Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48799)

- Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. (CVE-2025-48820)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5062560
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0055
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-36350
CVE CVE-2025-36357
CVE CVE-2025-47159
CVE CVE-2025-47971
CVE CVE-2025-47972
CVE CVE-2025-47973
CVE CVE-2025-47975
CVE CVE-2025-47976
CVE CVE-2025-47980
CVE CVE-2025-47981
CVE CVE-2025-47982
CVE CVE-2025-47984
CVE CVE-2025-47985
CVE CVE-2025-47986
CVE CVE-2025-47987
CVE CVE-2025-47991
CVE CVE-2025-47996
CVE CVE-2025-47998
CVE CVE-2025-47999
CVE CVE-2025-48000
CVE CVE-2025-48001
CVE CVE-2025-48799
CVE CVE-2025-48800
CVE CVE-2025-48803
CVE CVE-2025-48804
CVE CVE-2025-48805
CVE CVE-2025-48806
CVE CVE-2025-48808
CVE CVE-2025-48811
CVE CVE-2025-48814
CVE CVE-2025-48815
CVE CVE-2025-48816
CVE CVE-2025-48817
CVE CVE-2025-48818
CVE CVE-2025-48819
CVE CVE-2025-48820
CVE CVE-2025-48821
CVE CVE-2025-48822
CVE CVE-2025-48823
CVE CVE-2025-48824
CVE CVE-2025-49657
CVE CVE-2025-49658
CVE CVE-2025-49659
CVE CVE-2025-49660
CVE CVE-2025-49661
CVE CVE-2025-49663
CVE CVE-2025-49664
CVE CVE-2025-49665
CVE CVE-2025-49666
CVE CVE-2025-49667
CVE CVE-2025-49668
CVE CVE-2025-49669
CVE CVE-2025-49670
CVE CVE-2025-49671
CVE CVE-2025-49672
CVE CVE-2025-49673
CVE CVE-2025-49674
CVE CVE-2025-49675
CVE CVE-2025-49676
CVE CVE-2025-49678
CVE CVE-2025-49679
CVE CVE-2025-49680
CVE CVE-2025-49681
CVE CVE-2025-49683
CVE CVE-2025-49684
CVE CVE-2025-49686
CVE CVE-2025-49687
CVE CVE-2025-49688
CVE CVE-2025-49689
CVE CVE-2025-49691
CVE CVE-2025-49716
CVE CVE-2025-49721
CVE CVE-2025-49722
CVE CVE-2025-49725
CVE CVE-2025-49726
CVE CVE-2025-49727
CVE CVE-2025-49729
CVE CVE-2025-49730
CVE CVE-2025-49732
CVE CVE-2025-49740
CVE CVE-2025-49742
CVE CVE-2025-49744
CVE CVE-2025-49753
CVE CVE-2025-49760
CVE CVE-2025-55230
CVE CVE-2025-55231
MSKB 5062560
XREF MSFT:MS25-5062560
XREF IAVA:2025-A-0507-S
XREF IAVA:2025-A-0506-S
XREF IAVA:2025-A-0631-S
XREF CWE:20
XREF CWE:23
XREF CWE:59
XREF CWE:73
XREF CWE:122
XREF CWE:125
XREF CWE:126
XREF CWE:190
XREF CWE:191
XREF CWE:197
XREF CWE:200
XREF CWE:284
XREF CWE:306
XREF CWE:326
XREF CWE:349
XREF CWE:353
XREF CWE:362
XREF CWE:367
XREF CWE:400
XREF CWE:415
XREF CWE:416
XREF CWE:476
XREF CWE:591
XREF CWE:693
XREF CWE:787
XREF CWE:820
XREF CWE:822
XREF CWE:843
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5062560

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8246
261798 - KB5065427: Windows 10 Version 1607 / Windows Server 2016 Security Update (September 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5065427. It is, therefore, affected by multiple vulnerabilities

- SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks:
Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server HardeningSMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures. (CVE-2025-55234)

- Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. (CVE-2025-49734)

- Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. (CVE-2025-53796, CVE-2025-53797, CVE-2025-53798, CVE-2025-53806)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5065427
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.0073
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2025/09/09, Modified: 2025/10/29
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5065427

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8422
277997 - KB5071543: Windows 10 Version 1607 / Windows Server 2016 Security Update (December 2025)
-
Synopsis
The remote Windows host is affected by multiple vulnerabilities.
Description
The remote Windows host is missing security update 5071543. It is, therefore, affected by multiple vulnerabilities

- Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. (CVE-2025-62549)

- Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. (CVE-2025-62458)

- Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. (CVE-2025-62466)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply Security Update 5071543
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
8.1
EPSS Score
0.002
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-54100
CVE CVE-2025-59517
CVE CVE-2025-62455
CVE CVE-2025-62458
CVE CVE-2025-62466
CVE CVE-2025-62470
CVE CVE-2025-62472
CVE CVE-2025-62473
CVE CVE-2025-62474
CVE CVE-2025-62549
CVE CVE-2025-62565
CVE CVE-2025-62567
CVE CVE-2025-62571
CVE CVE-2025-62573
CVE CVE-2025-64661
MSKB 5071543
XREF MSFT:MS25-5071543
XREF IAVA:2025-A-0916
XREF IAVA:2025-A-0917
Plugin Information
Published: 2025/12/09, Modified: 2025/12/12
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5071543

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.8688
56175 - MS11-072: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host is running a version of Microsoft Office, Excel, or a related product that is affected by several vulnerabilities.

If an attacker can trick a user on the affected host into opening a specially crafted Excel file, he could leverage this issue to execute arbitrary code subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Excel Viewer, Office Compatability Pack, Excel Services, and Excel Web App.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.6237
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 49476
BID 49477
BID 49478
BID 49517
BID 49518
CVE CVE-2011-1986
CVE CVE-2011-1987
CVE CVE-2011-1988
CVE CVE-2011-1989
CVE CVE-2011-1990
MSKB 2553070
MSKB 2553072
MSKB 2553073
MSKB 2553074
MSKB 2553075
MSKB 2553089
MSKB 2553090
MSKB 2553091
MSKB 2553093
MSKB 2553094
MSKB 2553095
MSKB 2553096
XREF MSFT:MS11-072
Plugin Information
Published: 2011/09/14, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Excel 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Excel.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6106.5005
56176 - MS11-073: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host is running a version of Microsoft Office that is potentially affected by two vulnerabilities :

- The application insecurely restricts the path used for loading external libraries when opening documents that use the .doc, .xls, or .ppt Office binary format and when the Office File Validation Add-in is not installed. This could lead to arbitrary code execution.
(CVE-2011-1980)

- The application may use an uninitialized object pointer when opening a Word document, which could lead to arbitrary code execution. (CVE-2011-1982)
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, and 2010.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.5972
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 49513
BID 49519
CVE CVE-2011-1980
CVE CVE-2011-1982
MSKB 2584052
MSKB 2584063
MSKB 2584066
XREF CERT:909022
XREF MSFT:MS11-073
Exploitable With
Core Impact (true) (true) (true)
Plugin Information
Published: 2011/09/14, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2584066
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.6106.5005
57275 - MS11-089: Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The version of Microsoft Office installed on the remote host has a use-after-free vulnerability. A remote attacker could exploit this by tricking a user into opening a specially crafted Word file, resulting in arbitrary code execution.
See Also
Solution
Microsoft has released a set of patches for Office 2007 SP2, 2007 SP3, 2010, and 2010 SP1.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.5475
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 50956
CVE CVE-2011-1983
MSKB 2589320
MSKB 2596785
XREF MSFT:MS11-089
Plugin Information
Published: 2011/12/13, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2589320
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Msptls.dll has not been patched.
Remote version : 14.0.4730.1010
Should be : 14.0.6112.5000
58659 - MS12-027: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2664258)
-
Synopsis
The remote Windows host is affected by a remote code execution vulnerability.
Description
A memory corruption issue exists in Windows common controls, specifically within the MSCOMCTL.TreeView, MSCOMCTL.ListView2, MSCOMCTL.TreeView2, and MSCOMCTL.ListView controls component of MSCOMCTL.OCX, due to improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this issue by convincing a user to view a specially crafted web page, resulting in the execution of arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007 and 2010; Office 2003 Web Components; SQL Server 2000, 2005, 2005 Express Edition, 2008, and 2008 R2; BizTalk Server 2002; Commerce Server 2002, 2007, 2009, and 2009 R2; Microsoft Visual FoxPro 8.0 and 9.0; and Visual Basic 6.0 Runtime.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9429
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 52911
CVE CVE-2012-0158
MSKB 983807
MSKB 983808
MSKB 983809
MSKB 2597112
MSKB 2598039
MSKB 2598041
MSKB 2641426
MSKB 2645025
MSKB 2647488
MSKB 2647490
MSKB 2655547
MSKB 2658674
MSKB 2658676
MSKB 2658677
XREF EDB-ID:18780
XREF MSFT:MS12-027
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
CANVAS (true) Core Impact (true) Metasploit (true)
Plugin Information
Published: 2012/04/11, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable controls do not have the kill bit set :

Class identifier : {996BF5E0-8044-4650-ADEB-0B013914E99C}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Class identifier : {9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Nessus determined these controls are being used by the following applications :

Product : Office 2010
Missing update : KB2598039
59038 - MS12-030: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2663830)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host is running a version of Microsoft Office, Excel, or a related product that is affected by several vulnerabilities.

If an attacker can trick a user on the affected host into opening a specially crafted Excel file, they could leverage these issues to execute arbitrary code subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Excel 2003, 2007, 2010, Office 2007, 2010, Excel Viewer, and Office Compatibility Pack.
Risk Factor
High
VPR Score
9.7
EPSS Score
0.6469
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 53342
BID 53373
BID 53374
BID 53375
BID 53376
BID 53379
CVE CVE-2012-0184
CVE CVE-2012-0185
CVE CVE-2012-0141
CVE CVE-2012-0142
CVE CVE-2012-0143
CVE CVE-2012-1847
MSKB 2553371
MSKB 2596842
MSKB 2597086
MSKB 2597161
MSKB 2597162
MSKB 2597166
MSKB 2597969
XREF MSFT:MS12-030
Plugin Information
Published: 2012/05/09, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Excel 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Excel.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6117.5003
61532 - MS12-057: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2731879)
-
Synopsis
Arbitrary code can be executed on the remote host through Microsoft Office.
Description
The remote Windows host has a version of Microsoft Office that is potentially affected by a remote code execution vulnerability.
Specially crafted Computer Graphics Metafile (CGM) graphics files can be used to exploit this vulnerability and allow an attacker to take control of an affected system.
See Also
Solution
Microsoft has released a set of patches for Office 2007 and 2010.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.5323
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 54876
CVE CVE-2012-2524
MSKB 2553260
MSKB 2589322
MSKB 2596615
MSKB 2596754
MSKB 2687501
MSKB 2687510
XREF MSFT:MS12-057
XREF IAVB:2012-B-0075
Plugin Information
Published: 2012/08/15, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2687501
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.6123.5001
61535 - MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)
-
Synopsis
The remote Windows host has a code execution vulnerability.
Description
There is an unspecified remote code execution vulnerability in Windows common controls, which is included in several Microsoft products. An attacker could exploit this by tricking a user into viewing a maliciously crafted web page, resulting in arbitrary code execution.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2003, 2007, and 2010, Office 2003 Web Components, Microsoft SQL Server 2000, Microsoft SQL Analysis Services 2000, Microsoft Commerce Server 2002, 2007, and 2009, Microsoft Host Integration Server 2004, Microsoft Visual Fox Pro 8.0 and 9.0, and Visual Basic 6.0 Runtime.
Risk Factor
High
VPR Score
9.8
EPSS Score
0.9195
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 54948
CVE CVE-2012-1856
MSKB 983811
MSKB 983812
MSKB 983813
MSKB 2597986
MSKB 2687441
MSKB 2726929
MSKB 2708437
MSKB 2708940
MSKB 2708941
MSKB 2711207
MSKB 2716389
MSKB 2716390
MSKB 2716392
MSKB 2716393
XREF MSFT:MS12-060
XREF CISA-KNOWN-EXPLOITED:2022/03/24
Exploitable With
Core Impact (true)
Plugin Information
Published: 2012/08/15, Modified: 2022/04/11
Plugin Output

tcp/445/cifs


The following vulnerable controls do not have the kill bit set :

Class identifier : {24B224E0-9545-4A2F-ABD5-86AA8A849385}
Filename : C:\Windows\SysWOW64\MSCOMCTL.OCX
Installed version : 6.1.98.18

Nessus determined these controls are being used by the following applications :

Product : Office 2010
Missing Update : KB2597986
62459 - MS12-064: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319)
-
Synopsis
A Microsoft Office component installed on the remote host is affected by multiple remote code execution vulnerabilities.
Description
The version of Office, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps, and/or Microsoft Share Point Server installed on the remote host is affected by multiple remote code execution vulnerabilities :

- A flaw in the way Microsoft Word handles Word files can allow an attacker to execute arbitrary code by tricking a user into opening a specially crafted Word file.
(CVE-2012-0182)

- A flaw in the way Microsoft Office handles RTF files can be exploited to execute arbitrary code by tricking a user into opening a specially crafted RTF document.
(CVE-2012-2528)
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps and Microsoft SharePoint Server.
Risk Factor
High
VPR Score
9.7
EPSS Score
0.5685
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 55780
BID 55781
CVE CVE-2012-0182
CVE CVE-2012-2528
MSKB 2553488
MSKB 2598237
MSKB 2687314
MSKB 2687315
MSKB 2687401
MSKB 2687483
MSKB 2687485
XREF MSFT:MS12-064
Plugin Information
Published: 2012/10/10, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6123.5005
62908 - MS12-076: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2720184)
-
Synopsis
It is possible to execute arbitrary code on the remote host through Microsoft Excel.
Description
The remote Windows host is running a version of Microsoft Excel that is affected by the following vulnerabilities :

- A heap-based buffer overflow vulnerability exists due to the way the application handles memory when opening Excel files. (CVE-2012-1885)

- A memory corruption vulnerability exists due to the way the application handles memory when opening Excel files. (CVE-2012-1886)

- A use-after-free vulnerability exists due to the way the application handles memory when opening Excel files. (CVE-2012-1887)

- A stack-based buffer overflow vulnerability exists due to the way the application handles data structures while parsing Excel files. (CVE-2012-2543)

If an attacker can trick a user on the affected host into opening a specially crafted Excel file, it may be possible to leverage these issues to execute arbitrary code subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Excel 2003, 2007, 2010, Excel Viewer, and Office Compatibility Pack.
Risk Factor
High
VPR Score
9.7
EPSS Score
0.6594
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 56425
BID 56426
BID 56430
BID 56431
CVE CVE-2012-1885
CVE CVE-2012-1886
CVE CVE-2012-1887
CVE CVE-2012-2543
MSKB 2597126
MSKB 2687307
MSKB 2687311
MSKB 2687313
MSKB 2687481
XREF MSFT:MS12-076
Plugin Information
Published: 2012/11/14, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Excel 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Excel.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6126.5003
63226 - MS12-079: Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642)
-
Synopsis
A Microsoft Office component installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Office, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps, and/or Microsoft Share Point Server installed on the remote host has a remote code execution vulnerability. This is due to the way that Microsoft Office software parses RTF data and could allow an attacker to execute arbitrary code by tricking a user into opening a specially crafted RTF file.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, Microsoft Office Web Apps and Microsoft SharePoint Server.
Risk Factor
High
VPR Score
9.4
EPSS Score
0.8553
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 56834
CVE CVE-2012-2539
MSKB 2760405
MSKB 2760410
MSKB 2687412
MSKB 2760416
MSKB 2760421
MSKB 2760497
MSKB 2760498
XREF MSFT:MS12-079
XREF CISA-KNOWN-EXPLOITED:2022/04/18
Plugin Information
Published: 2012/12/11, Modified: 2022/03/29
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.6129.5000
69828 - MS13-068: Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (2756473)
-
Synopsis
The version of Microsoft Office installed on the remote Windows is affected by a code execution vulnerability.
Description
The Outlook component of Microsoft Office is affected by a remote code execution vulnerability due to a flaw in how Outlook parses S/MIME messages. It is possible for a remote attacker to execute arbitrary code if a user opens or previews a specially crafted email in an affected version of Outlook.
See Also
Solution
Microsoft has released a set of patches for Office 2007 and 2010.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.3672
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 62188
CVE CVE-2013-3870
MSKB 2825999
MSKB 2794707
XREF MSFT:MS13-068
Plugin Information
Published: 2013/09/11, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2794707
- C:\Program Files (x86)\Microsoft Office\Office14\\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Should be : 14.0.7105.5000
69832 - MS13-072: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537)
-
Synopsis
The Microsoft Office component installed on the remote host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host is running a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, or Microsoft Word Viewer that is affected by the following remote code execution vulnerabilities :

- A remote code execution vulnerability exists due to the way the XML parser used by Word resolves external entities. (CVE-2013-3160)

- Remote code execution vulnerabilities exist due to memory corruption issues in the way that Microsoft Office parses files.
(CVE-2013-3847, CVE-2013-3848, CVE-2013-3849, CVE-2013-3850, CVE-2013-3851, CVE-2013-3852, CVE-2013-3853, CVE-2013-3854, CVE-2013-3855, CVE-2013-3856, CVE-2013-3857, CVE-2013-3858)

If an attacker can trick a user on the affected host into opening a specially crafted file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, and Microsoft Word Viewer.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.6689
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 62162
BID 62165
BID 62168
BID 62169
BID 62170
BID 62171
BID 62216
BID 62217
BID 62220
BID 62222
BID 62223
BID 62224
BID 62226
CVE CVE-2013-3160
CVE CVE-2013-3847
CVE CVE-2013-3848
CVE CVE-2013-3849
CVE CVE-2013-3850
CVE CVE-2013-3851
CVE CVE-2013-3852
CVE CVE-2013-3853
CVE CVE-2013-3854
CVE CVE-2013-3855
CVE CVE-2013-3856
CVE CVE-2013-3857
CVE CVE-2013-3858
MSKB 2597973
MSKB 2760411
MSKB 2760769
MSKB 2760823
MSKB 2767773
MSKB 2767913
MSKB 2817474
MSKB 2817682
MSKB 2817683
MSKB 2845537
XREF MSFT:MS13-072
XREF IAVA:2013-A-0178-S
Plugin Information
Published: 2013/09/11, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7106.5001

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7106.5001
69833 - MS13-073: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2858300))
-
Synopsis
It is possible to execute arbitrary code on the remote host through Microsoft Excel.
Description
The remote Windows host is running a version of Microsoft Excel that is affected by the following vulnerabilities :

- Two memory corruption vulnerabilities exist due to the way the application handles objects in memory when parsing Office files. (CVE-2013-1315 / CVE-2013-3158)

- An information disclosure vulnerability exists due to the way the application parses XML files containing external entities. (CVE-2013-3159)

If an attacker can trick a user on the affected host into opening a specially crafted Excel file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Excel 2003, 2007, 2010, 2013, Excel Viewer, and Office Compatibility Pack.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.7368
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 62167
BID 62219
BID 62225
CVE CVE-2013-1315
CVE CVE-2013-3158
CVE CVE-2013-3159
MSKB 2858300
MSKB 2760583
MSKB 2760588
MSKB 2760590
MSKB 2760597
MSKB 2768017
MSKB 2810048
XREF MSFT:MS13-073
Plugin Information
Published: 2013/09/11, Modified: 2019/12/13
Plugin Output

tcp/445/cifs



Product : Excel 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Excel.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7104.5000
69834 - MS13-074: Vulnerabilities in Microsoft Access Could Allow Remote Code Execution (2848637)
-
Synopsis
It is possible to execute arbitrary code on the remote host through Microsoft Access.
Description
The remote Windows host is running a version of Microsoft Access that is affected by multiple remote code execution vulnerabilities. These vulnerabilities are due to the way that Microsoft Access parses content in Access files.

If an attacker can trick a user on the affected host into opening a specially crafted Access file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013.
Risk Factor
High
VPR Score
7.4
EPSS Score
0.5802
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.7 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
BID 62229
BID 62230
BID 62231
CVE CVE-2013-3155
CVE CVE-2013-3156
CVE CVE-2013-3157
MSKB 2596825
MSKB 2687423
MSKB 2810009
MSKB 2848637
XREF MSFT:MS13-074
XREF IAVB:2013-B-0099-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2013/09/11, Modified: 2025/03/13
Plugin Output

tcp/445/cifs



KB : 2687423
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\Acecore.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.7102.1000
70337 - MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)
-
Synopsis
The Microsoft Office component installed on the remote host is affected by multiple remote code execution vulnerabilities.
Description
The remote Windows host is running a version of Microsoft Office, Microsoft Excel, Office Compatibility Pack, or Microsoft Excel Viewer that is affected by remote code execution vulnerabilities in the way that Microsoft Excel parses file contents. (CVE-2013-3889, CVE-2013-3890).

If an attacker can trick a user on the affected host into opening a specially crafted file, it may be possible to leverage these issues to read arbitrary files on the target system or execute arbitrary code, subject to the user's privileges.
See Also
Solution
Microsoft has released a set of patches for Excel 2007, Excel 2010, Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and Office Compatibility Pack.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.6499
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 62824
BID 62829
CVE CVE-2013-3889
CVE CVE-2013-3890
MSKB 2760585
MSKB 2760591
MSKB 2817623
MSKB 2826023
MSKB 2826033
MSKB 2826035
MSKB 2827238
MSKB 2827324
MSKB 2827326
MSKB 2827328
MSKB 2885080
XREF MSFT:MS13-085
Plugin Information
Published: 2013/10/09, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



Product : Excel 2010
File : C:\Program Files (x86)\Microsoft Office\Office14
Installed version : 14.0.6024.1000
Fixed version : 14.0.7109.5000

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Oart.dll
Installed version : 14.0.6024.1000
Fixed version : 14.0.7108.5000

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\Oartconv.dll
Installed version : 14.0.6024.1000
Fixed version : 14.0.7108.5000
71941 - MS14-001: Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)
-
Synopsis
The remote host is affected by multiple memory corruption vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, or Microsoft Office Web Apps that is affected by one or more unspecified memory corruption vulnerabilities. By tricking a user into opening a specially crafted file, it may be possible for a remote attacker to take complete control of the system or execute arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
5.9
EPSS Score
0.3724
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 64726
BID 64727
BID 64728
CVE CVE-2014-0258
CVE CVE-2014-0259
CVE CVE-2014-0260
MSKB 2827224
MSKB 2837577
MSKB 2837596
MSKB 2837615
MSKB 2837617
MSKB 2837625
MSKB 2863834
MSKB 2863866
MSKB 2863867
MSKB 2863879
MSKB 2863901
MSKB 2863902
XREF MSFT:MS14-001
XREF IAVA:2014-A-0006-S
Plugin Information
Published: 2014/01/14, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7113.5001

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7113.5001
73413 - MS14-017: Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660)
-
Synopsis
The remote host is affected by multiple memory corruption vulnerabilities.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, or Microsoft Office Web Apps that is affected by one or more unspecified memory corruption vulnerabilities. By tricking a user into opening a specially crafted file, it may be possible for a remote attacker to take complete control of the system or execute arbitrary code.
See Also
Solution
Microsoft has released a set of patches for Office 2003, 2007, 2010, 2013, Office Compatibility Pack, Microsoft Word Viewer, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
9.6
EPSS Score
0.9313
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 66385
BID 66614
BID 66629
CVE CVE-2014-1757
CVE CVE-2014-1758
CVE CVE-2014-1761
MSKB 2863910
MSKB 2878220
MSKB 2878221
MSKB 2878236
MSKB 2878237
MSKB 2863907
MSKB 2878303
MSKB 2878304
MSKB 2878219
MSKB 2863919
MSKB 2863926
XREF CERT:882841
XREF IAVA:2014-A-0049-S
XREF MSFT:MS14-017
XREF CISA-KNOWN-EXPLOITED:2022/08/15
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2014/04/08, Modified: 2023/02/16
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7121.5004

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version :
Fixed version : 14.0.7121.5004
78437 - MS14-061: Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
-
Synopsis
The remote host is affected by a remote code execution vulnerability.
Description
The remote Windows host has a version of Microsoft Office, Microsoft Word, Office Compatibility Pack, SharePoint Server, or Microsoft Office Web Apps that is affected by remote code execution vulnerability due to a flaw in parsing Word documents. This vulnerability can be triggered by tricking a user into opening a specially crafted Word document.
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, Office Compatibility Pack, SharePoint Server, and Office Web Apps.
Risk Factor
High
VPR Score
6.7
EPSS Score
0.3203
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 70360
CVE CVE-2014-4117
MSKB 2883031
MSKB 2883032
MSKB 2883008
MSKB 2883013
MSKB 2883098
MSKB 2889827
XREF MSFT:MS14-061
Plugin Information
Published: 2014/10/15, Modified: 2018/07/30
Plugin Output

tcp/445/cifs



Product : Word 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\WinWord.exe
Installed version : 14.0.6024.1000
Fixed version : 14.0.7134.5000

Product : Microsoft Office 2010
File : C:\Program Files (x86)\Microsoft Office\Office14\\Wwlib.dll
Installed version : 14.0.6024.1000
Fixed version : 14.0.7134.5000
27525 - Microsoft Office Service Pack Out of Date
-
Synopsis
The remote office suite is not up to date.
Description
The remote version of Microsoft Office has no service pack or the one installed is no longer supported.
See Also
Solution
Install the latest service pack.
Risk Factor
High
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
Plugin Information
Published: 2007/10/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The remote Microsoft Office 2010 system has Service Pack 1 applied.
The system should have Office 2010 Service Pack 2 installed.
63155 - Microsoft Windows Unquoted Service Path Enumeration
-
Synopsis
The remote Windows host has at least one service installed that uses an unquoted service path.
Description
The remote Windows host has at least one service installed that uses an unquoted service path, which contains at least one whitespace. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service.

Note that this is a generic test that will flag any application affected by the described vulnerability.
See Also
Solution
Ensure that any services that contain a space in the path enclose the path in quotes.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0078
CVSS v2.0 Base Score
6.9 (CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.4 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 58591
BID 58617
BID 65873
BID 68520
CVE CVE-2013-1609
CVE CVE-2014-0759
CVE CVE-2014-5455
XREF ICSA:14-058-01
XREF EDB-ID:34037
Exploitable With
Metasploit (true)
Plugin Information
Published: 2012/12/05, Modified: 2025/05/29
Plugin Output

tcp/445/cifs


Nessus found the following service with an untrusted path :
NetPipeActivator : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
240630 - Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144)
-
Synopsis
A text editor on the remote Windows host is affected by privilege escalation.
Description
The version of Notepad++ installed on the remote host is prior to 8.8.2. It is, therefore, affected by a privilege escalation vulnerability:

- Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.
(CVE-2025-49144) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to Notepad++ 8.8.2 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
8.4
EPSS Score
0.0001
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49144
XREF IAVA:2025-A-0452
Plugin Information
Published: 2025/06/26, Modified: 2025/11/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Notepad++
Installed version : 8.6.6.0
Fixed version : 8.8.2
193574 - Oracle Java (Apr 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u401, 20.3.13, 21.3.9, 11.0.23, 17.0.10, 21.0.3, 22, and perf versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the April 2024 CPU advisory.

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition.(CVE-2023-41993)

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2 and 22. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GraalVM for JDK executes to compromise Oracle GraalVM for JDK. While the vulnerability is in Oracle GraalVM for JDK, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM for JDK accessible data as well as unauthorized access to critical data or complete access to all Oracle GraalVM for JDK accessible data.
(CVE-2024-21892)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.23, 17.0.10, 21.0.3, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.3, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. (CVE-2024-21011)


Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the April 2024 Oracle Critical Patch Update advisory.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.2153
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-32643
CVE CVE-2023-41993
CVE CVE-2024-20954
CVE CVE-2024-21002
CVE CVE-2024-21003
CVE CVE-2024-21004
CVE CVE-2024-21005
CVE CVE-2024-21011
CVE CVE-2024-21012
CVE CVE-2024-21068
CVE CVE-2024-21085
CVE CVE-2024-21094
CVE CVE-2024-21098
CVE CVE-2024-21892
XREF IAVA:2024-A-0239
XREF CISA-KNOWN-EXPLOITED:2023/10/16
XREF IAVA:2024-A-0239
Plugin Information
Published: 2024/04/19, Modified: 2025/03/14
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.411 or greater
209282 - Oracle Java SE Multiple Vulnerabilities (October 2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2024 CPU advisory.

- Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK. (CVE-2024-36138)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2023-42950)

- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:
JavaFX (libxml2)). Supported versions that are affected are Oracle Java SE: 8u421; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. (CVE-2024-25062)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0074
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
6.1 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/10/18, Modified: 2025/11/05
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.431 or greater
271249 - Oracle Java SE Multiple Vulnerabilities (October 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u461, 11.0.28, 17.0.16, 21.0.8, 25, versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the October 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)). Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. (CVE-2025-31257)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53057)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. (CVE-2025-53066)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
VPR Score
9.2
EPSS Score
0.0009
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
STIG Severity
I
References
Plugin Information
Published: 2025/10/23, Modified: 2025/12/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.471 or greater
242073 - RARLAB WinRAR < 7.12 Beta 1 Directory Traversal Remote Code Execution (CVE-2025-6218)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal remote code execution vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.12 Beta 1. It is, therefore, affected by a vulnerability:

- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. (CVE-2025-6218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.12 Beta 1 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.4
EPSS Score
0.0029
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-6218
XREF IAVA:2025-A-0227
XREF ZDI:ZDI-25-409
XREF CISA-KNOWN-EXPLOITED:2025/12/30
Plugin Information
Published: 2025/07/14, Modified: 2025/12/09
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.12 Beta 1
248462 - RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088)
-
Synopsis
The remote Windows host has an application installed which is affected by a directory traversal vulnerability.
Description
The remote host is running RARLAB WinRAR, an archive manager for Windows, whose reported version is prior to 7.13. It is, therefore, affected by a vulnerability:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to RARLAB WinRAR version 7.13 or later.
Risk Factor
Critical
CVSS v4.0 Base Score
8.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.5
EPSS Score
0.0562
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.3 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2025-8088
XREF CISA-KNOWN-EXPLOITED:2025/09/02
XREF IAVA:2025-A-0608
Plugin Information
Published: 2025/08/11, Modified: 2025/08/21
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.13

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/1433/mssql


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
-
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
VPR Score
6.1
EPSS Score
0.4002
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output

tcp/3389/msrdp


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

111693 - Security Updates for Microsoft .NET Framework (August 2018)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments. The vulnerability is caused when .NET Framework is used in high-load/high-density network connections where content from one stream can blend into another stream.
(CVE-2018-8360)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0313
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 104986
CVE CVE-2018-8360
MSKB 4343887
MSKB 4343885
MSKB 4343909
MSKB 4344147
MSKB 4344146
MSKB 4344145
MSKB 4344144
MSKB 4344165
MSKB 4344167
MSKB 4344166
MSKB 4344149
MSKB 4344148
MSKB 4344152
MSKB 4343897
MSKB 4343892
MSKB 4344150
MSKB 4344151
MSKB 4344178
MSKB 4344153
MSKB 4344176
MSKB 4344177
MSKB 4344175
MSKB 4344172
MSKB 4344173
MSKB 4344171
XREF MSFT:MS18-4343887
XREF MSFT:MS18-4343885
XREF MSFT:MS18-4343909
XREF MSFT:MS18-4344147
XREF MSFT:MS18-4344146
XREF MSFT:MS18-4344145
XREF MSFT:MS18-4344144
XREF MSFT:MS18-4344165
XREF MSFT:MS18-4344167
XREF MSFT:MS18-4344166
XREF MSFT:MS18-4344149
XREF MSFT:MS18-4344148
XREF MSFT:MS18-4344152
XREF MSFT:MS18-4343897
XREF MSFT:MS18-4343892
XREF MSFT:MS18-4344150
XREF MSFT:MS18-4344151
XREF MSFT:MS18-4344178
XREF MSFT:MS18-4344153
XREF MSFT:MS18-4344176
XREF MSFT:MS18-4344177
XREF MSFT:MS18-4344175
XREF MSFT:MS18-4344172
XREF MSFT:MS18-4344173
XREF MSFT:MS18-4344171
Plugin Information
Published: 2018/08/14, Modified: 2019/11/04
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4343887

C:\Windows\Microsoft.NET\Framework\v2.0.50727\sos.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8793

08_2018 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\sos.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3132.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4343887

C:\Windows\Microsoft.NET\Framework\v2.0.50727\sos.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8793

139598 - Security Updates for Microsoft .NET Framework (August 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. (CVE-2020-1476)

- A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. (CVE-2020-1046)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.068
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1046
CVE CVE-2020-1476
MSKB 4569751
MSKB 4571709
MSKB 4569748
MSKB 4569749
MSKB 4569746
MSKB 4571692
MSKB 4569745
MSKB 4571741
MSKB 4570506
MSKB 4570507
MSKB 4571694
MSKB 4570505
MSKB 4570502
MSKB 4570503
MSKB 4570500
MSKB 4570501
MSKB 4570508
MSKB 4570509
XREF MSFT:MS20-4569751
XREF MSFT:MS20-4571709
XREF MSFT:MS20-4569748
XREF MSFT:MS20-4569749
XREF MSFT:MS20-4569746
XREF MSFT:MS20-4571692
XREF MSFT:MS20-4569745
XREF MSFT:MS20-4571741
XREF MSFT:MS20-4570506
XREF MSFT:MS20-4570507
XREF MSFT:MS20-4571694
XREF MSFT:MS20-4570505
XREF MSFT:MS20-4570502
XREF MSFT:MS20-4570503
XREF MSFT:MS20-4570500
XREF MSFT:MS20-4570501
XREF MSFT:MS20-4570508
XREF MSFT:MS20-4570509
XREF IAVA:2020-A-0368-S
XREF CEA-ID:CEA-2020-0101
Plugin Information
Published: 2020/08/14, Modified: 2022/12/06
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4571694

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.web.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8951

08_2020 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.web.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3650.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4571694

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.web.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8951

122234 - Security Updates for Microsoft .NET Framework (February 2019)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2019-0613)

- A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's. An attacker who successfully exploited this vulnerability could use it to bypass security logic intended to ensure that a user-provided URL belonged to a specific hostname or a subdomain of that hostname. This could be used to cause privileged communication to be made to an untrusted service as if it was a trusted service.
(CVE-2019-0657)

- An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system.
(CVE-2019-0663)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1904
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 106872
BID 106890
CVE CVE-2019-0613
CVE CVE-2019-0657
CVE CVE-2019-0663
MSKB 4483482
MSKB 4483483
MSKB 4483481
MSKB 4483484
MSKB 4487020
MSKB 4487026
MSKB 4483449
MSKB 4483468
MSKB 4483469
MSKB 4486996
MSKB 4483474
MSKB 4487018
MSKB 4483473
MSKB 4487017
MSKB 4483454
MSKB 4483451
MSKB 4483450
MSKB 4483453
MSKB 4483452
MSKB 4483455
MSKB 4483472
MSKB 4483457
MSKB 4483456
MSKB 4483459
MSKB 4483458
MSKB 4483470
XREF MSFT:MS19-4483482
XREF MSFT:MS19-4483483
XREF MSFT:MS19-4483481
XREF MSFT:MS19-4483484
XREF MSFT:MS19-4487020
XREF MSFT:MS19-4487026
XREF MSFT:MS19-4483449
XREF MSFT:MS19-4483468
XREF MSFT:MS19-4483469
XREF MSFT:MS19-4486996
XREF MSFT:MS19-4483474
XREF MSFT:MS19-4487018
XREF MSFT:MS19-4483473
XREF MSFT:MS19-4487017
XREF MSFT:MS19-4483454
XREF MSFT:MS19-4483451
XREF MSFT:MS19-4483450
XREF MSFT:MS19-4483453
XREF MSFT:MS19-4483452
XREF MSFT:MS19-4483455
XREF MSFT:MS19-4483472
XREF MSFT:MS19-4483457
XREF MSFT:MS19-4483456
XREF MSFT:MS19-4483459
XREF MSFT:MS19-4483458
XREF MSFT:MS19-4483470
Plugin Information
Published: 2019/02/15, Modified: 2020/04/28
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4487026

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8803

02_2019 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3353.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4487026

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8803

121021 - Security Updates for Microsoft .NET Framework (January 2019)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross- origin Resource Sharing (CORS) configurations. An attacker who successfully exploited the vulnerability could retrieve content, that is normally restricted, from a web application. The security update addresses the vulnerability by enforcing CORS configuration to prevent its bypass. (CVE-2019-0545)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0674
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0545
MSKB 4480051
MSKB 4480054
MSKB 4480055
MSKB 4480056
MSKB 4480057
MSKB 4480058
MSKB 4480059
MSKB 4480061
MSKB 4480062
MSKB 4480063
MSKB 4480064
MSKB 4480070
MSKB 4480071
MSKB 4480072
MSKB 4480074
MSKB 4480075
MSKB 4480076
MSKB 4480083
MSKB 4480084
MSKB 4480085
MSKB 4480086
MSKB 4480961
MSKB 4480962
MSKB 4480966
MSKB 4480973
MSKB 4480978
XREF MSFT:MS19-4480051
XREF MSFT:MS19-4480054
XREF MSFT:MS19-4480055
XREF MSFT:MS19-4480056
XREF MSFT:MS19-4480057
XREF MSFT:MS19-4480058
XREF MSFT:MS19-4480059
XREF MSFT:MS19-4480061
XREF MSFT:MS19-4480062
XREF MSFT:MS19-4480063
XREF MSFT:MS19-4480064
XREF MSFT:MS19-4480070
XREF MSFT:MS19-4480071
XREF MSFT:MS19-4480072
XREF MSFT:MS19-4480074
XREF MSFT:MS19-4480075
XREF MSFT:MS19-4480076
XREF MSFT:MS19-4480083
XREF MSFT:MS19-4480084
XREF MSFT:MS19-4480085
XREF MSFT:MS19-4480086
XREF MSFT:MS19-4480961
XREF MSFT:MS19-4480962
XREF MSFT:MS19-4480966
XREF MSFT:MS19-4480973
XREF MSFT:MS19-4480978
Plugin Information
Published: 2019/01/08, Modified: 2019/10/31
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4480961

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8801

01_2019 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3314.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4480961

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8801

126600 - Security Updates for Microsoft .NET Framework (July 2019)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys. This vulnerability allows an attacker to impersonate another user, which can lead to elevation of privileges. The vulnerability exists in WCF, WIF 3.5 and above in .NET Framework, WIF 1.0 component in Windows, WIF Nuget package, and WIF implementation in SharePoint. An unauthenticated attacker can exploit this by signing a SAML token with any arbitrary symmetric key. This security update addresses the issue by ensuring all versions of WCF and WIF validate the key used to sign SAML tokens correctly.
(CVE-2019-1006)

- A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2019-1113)

- A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET web application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET application. The update addresses the vulnerability by correcting how the .NET web application handles web requests. (CVE-2019-1083)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3372
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 108977
BID 108981
CVE CVE-2019-1006
CVE CVE-2019-1083
CVE CVE-2019-1113
MSKB 4507435
MSKB 4507460
MSKB 4507423
MSKB 4507422
MSKB 4507421
MSKB 4507420
MSKB 4507414
MSKB 4507419
MSKB 4507412
MSKB 4507413
MSKB 4507411
MSKB 4506991
MSKB 4507450
MSKB 4506987
MSKB 4506986
MSKB 4507455
MSKB 4506989
MSKB 4506988
MSKB 4507458
XREF MSFT:MS19-4507435
XREF MSFT:MS19-4507460
XREF MSFT:MS19-4507423
XREF MSFT:MS19-4507422
XREF MSFT:MS19-4507421
XREF MSFT:MS19-4507420
XREF MSFT:MS19-4507414
XREF MSFT:MS19-4507419
XREF MSFT:MS19-4507412
XREF MSFT:MS19-4507413
XREF MSFT:MS19-4507411
XREF MSFT:MS19-4506991
XREF MSFT:MS19-4507450
XREF MSFT:MS19-4506987
XREF MSFT:MS19-4506986
XREF MSFT:MS19-4507455
XREF MSFT:MS19-4506989
XREF MSFT:MS19-4506988
XREF MSFT:MS19-4507458
XREF IAVA:2019-A-0240-S
Plugin Information
Published: 2019/07/10, Modified: 2021/06/03
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4507460

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.workflow.runtime.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3440.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4507460
138464 - Security Updates for Microsoft .NET Framework (July 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the process responsible for deserialization of the XML content. (CVE-2020-1147)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.9343
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-1147
MSKB 4565489
MSKB 4565508
MSKB 4565511
MSKB 4565513
MSKB 4565627
MSKB 4565628
MSKB 4565630
MSKB 4565631
MSKB 4565633
MSKB 4566466
MSKB 4566467
MSKB 4566468
MSKB 4566469
MSKB 4566516
MSKB 4566517
MSKB 4566518
MSKB 4566519
MSKB 4566520
XREF IAVA:2020-A-0305-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
XREF MSFT:MS20-4565489
XREF MSFT:MS20-4565508
XREF MSFT:MS20-4565511
XREF MSFT:MS20-4565513
XREF MSFT:MS20-4565627
XREF MSFT:MS20-4565628
XREF MSFT:MS20-4565630
XREF MSFT:MS20-4565631
XREF MSFT:MS20-4565633
XREF MSFT:MS20-4566466
XREF MSFT:MS20-4566467
XREF MSFT:MS20-4566468
XREF MSFT:MS20-4566469
XREF MSFT:MS20-4566516
XREF MSFT:MS20-4566517
XREF MSFT:MS20-4566518
XREF MSFT:MS20-4566519
XREF MSFT:MS20-4566520
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2020/07/14, Modified: 2023/04/25
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4565511

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.configuration.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8949

07_2020 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.configuration.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3630.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4565511

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.configuration.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8949

109652 - Security Updates for Microsoft .NET Framework (May 2018)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. (CVE-2018-1039)

- A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET (or .NET core) application. The update addresses the vulnerability by correcting how .NET and .NET Core applications handle XML document processing.
(CVE-2018-0765)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0303
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
References
BID 104060
BID 104072
CVE CVE-2018-0765
CVE CVE-2018-1039
MSKB 4095512
MSKB 4095513
MSKB 4095514
MSKB 4095515
MSKB 4095517
MSKB 4095518
MSKB 4095519
MSKB 4095872
MSKB 4095873
MSKB 4095874
MSKB 4095875
MSKB 4095876
MSKB 4096235
MSKB 4096236
MSKB 4096237
MSKB 4096416
MSKB 4096417
MSKB 4096418
MSKB 4096494
MSKB 4096495
MSKB 4103716
MSKB 4103721
MSKB 4103723
MSKB 4103727
MSKB 4103731
XREF MSFT:MS18-4095512
XREF MSFT:MS18-4095513
XREF MSFT:MS18-4095514
XREF MSFT:MS18-4095515
XREF MSFT:MS18-4095517
XREF MSFT:MS18-4095518
XREF MSFT:MS18-4095519
XREF MSFT:MS18-4095872
XREF MSFT:MS18-4095873
XREF MSFT:MS18-4095874
XREF MSFT:MS18-4095875
XREF MSFT:MS18-4095876
XREF MSFT:MS18-4096235
XREF MSFT:MS18-4096236
XREF MSFT:MS18-4096237
XREF MSFT:MS18-4096416
XREF MSFT:MS18-4096417
XREF MSFT:MS18-4096418
XREF MSFT:MS18-4096494
XREF MSFT:MS18-4096495
XREF MSFT:MS18-4103716
XREF MSFT:MS18-4103721
XREF MSFT:MS18-4103723
XREF MSFT:MS18-4103727
XREF MSFT:MS18-4103731
Plugin Information
Published: 2018/05/09, Modified: 2019/11/08
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4103723

C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.security.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8784

125074 - Security Updates for Microsoft .NET Framework (May 2019)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. (CVE-2019-0864)

- A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET Framework (or .NET core) application. The update addresses the vulnerability by correcting how .NET Framework and .NET Core applications handle RegEx string processing. (CVE-2019-0820)

- A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests.
An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework or .NET Core application.
The update addresses the vulnerability by correcting how .NET Framework or .NET Core web applications handles web requests. (CVE-2019-0980, CVE-2019-0981)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.1
EPSS Score
0.0169
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 108207
BID 108232
BID 108241
BID 108245
CVE CVE-2019-0820
CVE CVE-2019-0864
CVE CVE-2019-0980
CVE CVE-2019-0981
MSKB 4499179
MSKB 4494440
MSKB 4499406
MSKB 4499409
MSKB 4499408
MSKB 4495611
MSKB 4499405
MSKB 4499407
MSKB 4499154
MSKB 4495610
MSKB 4499167
MSKB 4495613
MSKB 4495616
MSKB 4499181
MSKB 4498964
MSKB 4498961
MSKB 4495620
MSKB 4498963
MSKB 4498962
XREF MSFT:MS19-4499179
XREF MSFT:MS19-4494440
XREF MSFT:MS19-4499406
XREF MSFT:MS19-4499409
XREF MSFT:MS19-4499408
XREF MSFT:MS19-4495611
XREF MSFT:MS19-4499405
XREF MSFT:MS19-4499407
XREF MSFT:MS19-4499154
XREF MSFT:MS19-4495610
XREF MSFT:MS19-4499167
XREF MSFT:MS19-4495613
XREF MSFT:MS19-4495616
XREF MSFT:MS19-4499181
XREF MSFT:MS19-4498964
XREF MSFT:MS19-4498961
XREF MSFT:MS19-4495620
XREF MSFT:MS19-4498963
XREF MSFT:MS19-4498962
XREF CEA-ID:CEA-2019-0326
Plugin Information
Published: 2019/05/15, Modified: 2024/05/22
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4494440

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8806

05_2019 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3416.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4494440

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8806

136564 - Security Updates for Microsoft .NET Framework (May 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft .NET Framework installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. (CVE-2020-1108)

- An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. (CVE-2020-1066)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.2954
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.0 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2020-1066
CVE CVE-2020-1108
MSKB 4556812
MSKB 4556826
MSKB 4556807
MSKB 4556813
MSKB 4556406
MSKB 4556405
MSKB 4556404
MSKB 4556403
MSKB 4556402
MSKB 4556401
MSKB 4556400
MSKB 4556441
MSKB 4552926
MSKB 4552931
MSKB 4556399
MSKB 4552928
MSKB 4552929
XREF MSFT:MS20-4556812
XREF MSFT:MS20-4556826
XREF MSFT:MS20-4556807
XREF MSFT:MS20-4556813
XREF MSFT:MS20-4556406
XREF MSFT:MS20-4556405
XREF MSFT:MS20-4556404
XREF MSFT:MS20-4556403
XREF MSFT:MS20-4556402
XREF MSFT:MS20-4556401
XREF MSFT:MS20-4556400
XREF MSFT:MS20-4556441
XREF MSFT:MS20-4552926
XREF MSFT:MS20-4552931
XREF MSFT:MS20-4556399
XREF MSFT:MS20-4552928
XREF MSFT:MS20-4552929
XREF IAVA:2020-A-0207-S
Exploitable With
Core Impact (true)
Plugin Information
Published: 2020/05/13, Modified: 2023/01/30
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4556813

C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.runtime.serialization.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3620.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4556813
175450 - Security Updates for Microsoft SQL Server (April 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-23384) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVSS v3.0 Temporal Score
6.4 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.4
EPSS Score
0.0079
CVSS v2.0 Base Score
7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.5 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-23384
MSKB 5020863
MSKB 5021037
MSKB 5021045
MSKB 5021112
MSKB 5021123
MSKB 5021124
MSKB 5021125
MSKB 5021126
MSKB 5021127
MSKB 5021128
MSKB 5021129
MSKB 5021522
XREF MSFT:MS23-5020863
XREF MSFT:MS23-5021037
XREF MSFT:MS23-5021045
XREF MSFT:MS23-5021112
XREF MSFT:MS23-5021123
XREF MSFT:MS23-5021124
XREF MSFT:MS23-5021125
XREF MSFT:MS23-5021126
XREF MSFT:MS23-5021127
XREF MSFT:MS23-5021128
XREF MSFT:MS23-5021129
XREF MSFT:MS23-5021522
XREF IAVA:2023-A-0189-S
Plugin Information
Published: 2023/05/12, Modified: 2023/08/11
Plugin Output

tcp/445/cifs



KB : 5021125
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2101.7

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
249129 - Security Updates for Microsoft SQL Server (August 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An elevation of privilege vulnerability. (CVE-2025-53727)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-53727
MSKB 5063814
MSKB 5063756
MSKB 5063757
MSKB 5063758
MSKB 5063759
MSKB 5063760
MSKB 5063761
MSKB 5063762
XREF MSFT:MS25-5063814
XREF MSFT:MS25-5063756
XREF MSFT:MS25-5063757
XREF MSFT:MS25-5063758
XREF MSFT:MS25-5063759
XREF MSFT:MS25-5063760
XREF MSFT:MS25-5063761
XREF MSFT:MS25-5063762
XREF IAVA:2025-A-0599-S
XREF CWE:89
Plugin Information
Published: 2025/08/12, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5063758
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2140.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
207070 - Security Updates for Microsoft SQL Server (CVE-2024-43474) (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An information disclosure vulnerability. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2024-43474)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.051
CVSS v2.0 Base Score
7.8 (CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
5.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-43474
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2025/01/08
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
171604 - Security Updates for Microsoft SQL Server (February 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2023-21528, CVE-2023-21568, CVE-2023-21704, CVE-2023-21705, CVE-2023-21713, CVE-2023-21718)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5021126
-KB5021129
-KB5021522
-KB5021127
-KB5021045
-KB5021037
-KB5021128
-KB5021124
-KB5021125
-KB5020863
-KB5021112
-KB5021123
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.2 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
8.4
EPSS Score
0.0056
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-21528
CVE CVE-2023-21568
CVE CVE-2023-21704
CVE CVE-2023-21705
CVE CVE-2023-21713
CVE CVE-2023-21718
MSKB 5020863
MSKB 5021112
MSKB 5021126
MSKB 5021129
MSKB 5021522
MSKB 5021127
MSKB 5021045
MSKB 5021037
MSKB 5021128
MSKB 5021123
MSKB 5021124
MSKB 5021125
XREF MSFT:MS23-5020863
XREF MSFT:MS23-5021112
XREF MSFT:MS23-5021126
XREF MSFT:MS23-5021129
XREF MSFT:MS23-5021522
XREF MSFT:MS23-5021127
XREF MSFT:MS23-5021045
XREF MSFT:MS23-5021037
XREF MSFT:MS23-5021128
XREF MSFT:MS23-5021124
XREF MSFT:MS23-5021125
XREF IAVA:2023-A-0086
Plugin Information
Published: 2023/02/17, Modified: 2023/09/04
Plugin Output

tcp/445/cifs



KB : 5021125
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2101.7

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
145033 - Security Updates for Microsoft SQL Server (January 2021)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by an elevation of privilege vulnerability. An authenticated, remote attacker can exploit this issue, to gain elevated privileges.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4583456
-KB4583457
-KB4583458
-KB4583459
-KB4583460
-KB4583461
-KB4583462
-KB4583463
-KB4583465
Risk Factor
Medium
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0159
CVSS v2.0 Base Score
6.5 (CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
4.8 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-1636
MSKB 4583456
MSKB 4583457
MSKB 4583458
MSKB 4583459
MSKB 4583460
MSKB 4583461
MSKB 4583462
MSKB 4583463
MSKB 4583465
XREF IAVA:2021-A-0018-S
XREF MSFT:MS21-4583456
XREF MSFT:MS21-4583457
XREF MSFT:MS21-4583458
XREF MSFT:MS21-4583459
XREF MSFT:MS21-4583460
XREF MSFT:MS21-4583461
XREF MSFT:MS21-4583462
XREF MSFT:MS21-4583463
XREF MSFT:MS21-4583465
XREF CEA-ID:CEA-2021-0001
Plugin Information
Published: 2021/01/15, Modified: 2023/06/29
Plugin Output

tcp/445/cifs



KB : 4583458
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2080.9

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER

tcp/445/cifs



KB : 4583460
- C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2015.131.5026.0
Should be : 2015.131.5103.6

SQL Server Version : 13.0.5026.0 Express Edition
SQL Server Instance : SQLEXPRESS
216604 - Security Updates for Microsoft SQL Server (July 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-20701, CVE-2024-21303, CVE-2024-21308, CVE-2024-21317, CVE-2024-21331, CVE-2024-21332, CVE-2024-21333, CVE-2024-21335, CVE-2024-21373, CVE-2024-21398, CVE-2024-21414, CVE-2024-21415, CVE-2024-21425, CVE-2024-21428, CVE-2024-21449, CVE-2024-28928, CVE-2024-35256, CVE-2024-35271, CVE-2024-35272, CVE-2024-37318, CVE-2024-37319, CVE-2024-37320, CVE-2024-37321, CVE-2024-37322, CVE-2024-37323, CVE-2024-37324, CVE-2024-37326, CVE-2024-37327, CVE-2024-37328, CVE-2024-37329, CVE-2024-37330, CVE-2024-37331, CVE-2024-37332, CVE-2024-37333, CVE-2024-37334, CVE-2024-37336, CVE-2024-38087, CVE-2024-38088)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5040942
-KB5040939
-KB5040936
-KB5040986
-KB5040944
-KB5040948
-KB5040940
-KB5040946
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0692
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2024-20701
CVE CVE-2024-21303
CVE CVE-2024-21308
CVE CVE-2024-21317
CVE CVE-2024-21331
CVE CVE-2024-21332
CVE CVE-2024-21333
CVE CVE-2024-21335
CVE CVE-2024-21373
CVE CVE-2024-21398
CVE CVE-2024-21414
CVE CVE-2024-21415
CVE CVE-2024-21425
CVE CVE-2024-21428
CVE CVE-2024-21449
CVE CVE-2024-28928
CVE CVE-2024-35256
CVE CVE-2024-35271
CVE CVE-2024-35272
CVE CVE-2024-37318
CVE CVE-2024-37319
CVE CVE-2024-37320
CVE CVE-2024-37321
CVE CVE-2024-37322
CVE CVE-2024-37323
CVE CVE-2024-37324
CVE CVE-2024-37326
CVE CVE-2024-37327
CVE CVE-2024-37328
CVE CVE-2024-37329
CVE CVE-2024-37330
CVE CVE-2024-37331
CVE CVE-2024-37332
CVE CVE-2024-37333
CVE CVE-2024-37334
CVE CVE-2024-37336
CVE CVE-2024-38087
CVE CVE-2024-38088
MSKB 5040942
MSKB 5040939
MSKB 5040936
MSKB 5040986
MSKB 5040944
MSKB 5040948
MSKB 5040940
MSKB 5040946
XREF MSFT:MS24-5040942
XREF MSFT:MS24-5040939
XREF MSFT:MS24-5040936
XREF MSFT:MS24-5040986
XREF MSFT:MS24-5040944
XREF MSFT:MS24-5040948
XREF MSFT:MS24-5040940
XREF MSFT:MS24-5040946
XREF CWE:121
XREF CWE:122
XREF CWE:190
XREF CWE:415
XREF CWE:416
Plugin Information
Published: 2025/02/21, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



KB : 5040986
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2116.2

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
241544 - Security Updates for Microsoft SQL Server (July 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2025-49717)

- Information disclosure vulnerabilities. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2025-49718, CVE-2025-49719)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
VPR Score
8.1
EPSS Score
0.003
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-49717
CVE CVE-2025-49718
CVE CVE-2025-49719
MSKB 5058712
MSKB 5058713
MSKB 5058714
MSKB 5058716
MSKB 5058717
MSKB 5058718
MSKB 5058721
MSKB 5058722
XREF MSFT:MS25-5058712
XREF MSFT:MS25-5058713
XREF MSFT:MS25-5058714
XREF MSFT:MS25-5058716
XREF MSFT:MS25-5058717
XREF MSFT:MS25-5058718
XREF MSFT:MS25-5058721
XREF MSFT:MS25-5058722
XREF IAVA:2025-A-0492-S
XREF CWE:20
XREF CWE:122
XREF CWE:908
Plugin Information
Published: 2025/07/08, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



KB : 5058713
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2135.5

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
162393 - Security Updates for Microsoft SQL Server (June 2022)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2022-29143)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB5015371
-KB5014553
-KB5014351
-KB5014353
-KB5014354
-KB5014356
-KB5014365
-KB5014355
-KB5014165
-KB5014164
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0048
CVSS v2.0 Base Score
6.0 (CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2022-29143
MSKB 5015371
MSKB 5014553
MSKB 5014351
MSKB 5014353
MSKB 5014354
MSKB 5014356
MSKB 5014365
MSKB 5014355
MSKB 5014165
MSKB 5014164
XREF IAVA:2022-A-0244-S
XREF MSFT:MS22-5015371
XREF MSFT:MS22-5014553
XREF MSFT:MS22-5014351
XREF MSFT:MS22-5014353
XREF MSFT:MS22-5014354
XREF MSFT:MS22-5014356
XREF MSFT:MS22-5014365
XREF MSFT:MS22-5014355
XREF MSFT:MS22-5014165
XREF MSFT:MS22-5014164
Plugin Information
Published: 2022/06/17, Modified: 2024/10/23
Plugin Output

tcp/445/cifs



KB : 5014356
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2095.3

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER

tcp/445/cifs



KB : 5014365
- C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2015.131.5026.0
Should be : 2015.131.5108.50

SQL Server Version : 13.0.5026.0 Express Edition
SQL Server Instance : SQLEXPRESS
211472 - Security Updates for Microsoft SQL Server (November 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48994, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49001, CVE-2024-49002, CVE-2024-49003, CVE-2024-49004, CVE-2024-49005, CVE-2024-49006, CVE-2024-49007, CVE-2024-49008, CVE-2024-49009, CVE-2024-49010, CVE-2024-49011, CVE-2024-49012, CVE-2024-49013, CVE-2024-49014, CVE-2024-49015, CVE-2024-49016, CVE-2024-49017, CVE-2024-49018, CVE-2024-49021, CVE-2024-49043)
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0596
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-38255
CVE CVE-2024-43459
CVE CVE-2024-43462
CVE CVE-2024-48993
CVE CVE-2024-48994
CVE CVE-2024-48995
CVE CVE-2024-48996
CVE CVE-2024-48997
CVE CVE-2024-48998
CVE CVE-2024-48999
CVE CVE-2024-49000
CVE CVE-2024-49001
CVE CVE-2024-49002
CVE CVE-2024-49003
CVE CVE-2024-49004
CVE CVE-2024-49005
CVE CVE-2024-49006
CVE CVE-2024-49007
CVE CVE-2024-49008
CVE CVE-2024-49009
CVE CVE-2024-49010
CVE CVE-2024-49011
CVE CVE-2024-49012
CVE CVE-2024-49013
CVE CVE-2024-49014
CVE CVE-2024-49015
CVE CVE-2024-49016
CVE CVE-2024-49017
CVE CVE-2024-49018
CVE CVE-2024-49021
CVE CVE-2024-49043
MSKB 5046855
MSKB 5046856
MSKB 5046857
MSKB 5046858
MSKB 5046859
MSKB 5046860
MSKB 5046861
MSKB 5046862
XREF MSFT:MS24-5046855
XREF MSFT:MS24-5046856
XREF MSFT:MS24-5046857
XREF MSFT:MS24-5046858
XREF MSFT:MS24-5046859
XREF MSFT:MS24-5046860
XREF MSFT:MS24-5046861
XREF MSFT:MS24-5046862
XREF IAVA:2024-A-0731
Plugin Information
Published: 2024/11/15, Modified: 2024/11/18
Plugin Output

tcp/445/cifs



KB : 5046859
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2130.3

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
275459 - Security Updates for Microsoft SQL Server (November 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected a vulnerability:

- Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. (CVE-2025-59499)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-59499
MSKB 5068400
MSKB 5068401
MSKB 5068402
MSKB 5068403
MSKB 5068404
MSKB 5068405
MSKB 5068406
MSKB 5068407
XREF MSFT:MS25-5068400
XREF MSFT:MS25-5068401
XREF MSFT:MS25-5068402
XREF MSFT:MS25-5068403
XREF MSFT:MS25-5068404
XREF MSFT:MS25-5068405
XREF MSFT:MS25-5068406
XREF MSFT:MS25-5068407
XREF IAVA:2025-A-0848
Plugin Information
Published: 2025/11/14, Modified: 2025/11/14
Plugin Output

tcp/445/cifs



KB : 5068405
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2155.2

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
207067 - Security Updates for Microsoft SQL Server (September 2024)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- A remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2024-26186, CVE-2024-26191, CVE-2024-37335, CVE-2024-37338, CVE-2024-37339, CVE-2024-37340)

- An information disclosure vulnerability. An authenticated, remote attacker can exploit this to disclose sensitive database and file information. (CVE-2024-37337, CVE-2024-37342, CVE-2024-37966)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0464
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.7 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2024-26186
CVE CVE-2024-26191
CVE CVE-2024-37335
CVE CVE-2024-37337
CVE CVE-2024-37338
CVE CVE-2024-37339
CVE CVE-2024-37340
CVE CVE-2024-37342
CVE CVE-2024-37966
MSKB 5042578
MSKB 5042749
MSKB 5042211
MSKB 5042215
MSKB 5042214
MSKB 5042217
XREF MSFT:MS24-5042578
XREF MSFT:MS24-5042749
XREF MSFT:MS24-5042211
XREF MSFT:MS24-5042215
XREF MSFT:MS24-5042214
XREF MSFT:MS24-5042217
XREF IAVA:2024-A-0565-S
Plugin Information
Published: 2024/09/12, Modified: 2024/11/15
Plugin Output

tcp/445/cifs



KB : 5042214
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2120.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
261809 - Security Updates for Microsoft SQL Server (September 2025)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerabilities:

- Improper Handling of Exceptional Conditions in Newtonsoft.Json (CVE-2024-21907)

- An information disclosure vulnerability (CVE-2025-47997)

- A privilege escalation vulnerability (CVE-2025-55227)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0252
CVSS v2.0 Base Score
9.0 (CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2024-21907
CVE CVE-2025-47997
CVE CVE-2025-55227
MSKB 5065220
MSKB 5065221
MSKB 5065222
MSKB 5065223
MSKB 5065224
MSKB 5065225
MSKB 5065226
MSKB 5065227
XREF MSFT:MS25-5065220
XREF MSFT:MS25-5065221
XREF MSFT:MS25-5065222
XREF MSFT:MS25-5065223
XREF MSFT:MS25-5065224
XREF MSFT:MS25-5065225
XREF MSFT:MS25-5065226
XREF MSFT:MS25-5065227
XREF IAVA:2025-A-0669
XREF CWE:77
XREF CWE:200
XREF CWE:362
XREF CWE:755
Plugin Information
Published: 2025/09/09, Modified: 2025/09/17
Plugin Output

tcp/445/cifs



KB : 5065223
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2145.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
205300 - Security Updates for Microsoft SQL Server OLE DB Driver (July 2024)
-
Synopsis
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update.
Description
The Microsoft SQL Server OLE DB Driver installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability. An attacker could exploit the vulnerability by tricking an authenticated user (UI:R) into attempting to connect to a malicious SQL server database via a connection driver. This could result in the database returning malicious data that could cause arbitrary code execution on the client.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for the Microsoft SQL OLE DB Driver.
Risk Factor
Critical
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.0243
CVSS v2.0 Base Score
10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.4 (CVSS2#E:U/RL:OF/RC:C)
References
Plugin Information
Published: 2024/08/09, Modified: 2025/08/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Installed version : 18.7.2.0
Fixed version : 18.7.4
119598 - Security Updates for Outlook (December 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8587)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461576
-KB4461556
-KB4461544
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.4676
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8587
MSKB 4461576
MSKB 4461556
MSKB 4461544
XREF MSFT:MS18-4461576
XREF MSFT:MS18-4461556
XREF MSFT:MS18-4461544
Plugin Information
Published: 2018/12/11, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7226.5000
106807 - Security Updates for Outlook (February 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
(CVE-2018-0850)

- A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
(CVE-2018-0852)
See Also
Solution
Microsoft has released the following security updates to address this issue:
- KB4011682
- KB4011697
- KB4011711
- KB4011200
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3054
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 102866
BID 102871
CVE CVE-2018-0850
CVE CVE-2018-0852
MSKB 4011682
MSKB 4011697
MSKB 4011711
MSKB 4011200
XREF MSFT:MS18-4011682
XREF MSFT:MS18-4011697
XREF MSFT:MS18-4011711
XREF MSFT:MS18-4011200
XREF IAVA:2018-A-0051-S
Plugin Information
Published: 2018/02/13, Modified: 2025/10/29
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7194.5000
105699 - Security Updates for Outlook (January 2018)
-
Synopsis
The version of Outlook installed on the remote host is affected by a remote code execution vulnerability.
Description
The version of Microsoft Outlook installed on the remote host is missing a security update. It is, therefore, affected by a remote code execution vulnerability in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system, then install programs; view, change, or delete data; or create new accounts with full user rights.
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.3557
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
BID 102383
CVE CVE-2018-0791
MSKB 4011213
MSKB 4011273
MSKB 4011637
MSKB 4011626
XREF MSFT:MS18-4011213
XREF MSFT:MS18-4011273
XREF MSFT:MS18-4011637
XREF MSFT:MS18-4011626
XREF IAVA:2018-A-0009-S
Plugin Information
Published: 2018/01/09, Modified: 2021/06/03
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7192.5000
102035 - Security Updates for Outlook (July 2017)
-
Synopsis
An application installed on the remote Windows host is affected by multiple vulnerabilities.
Description
The Microsoft Office or Outlook application installed on the remote Windows host is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- A security feature bypass vulnerability exists in Microsoft Office due to improper handling of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open and interact with a specially crafted document file, to bypass security measures and execute arbitrary commands.
(CVE-2017-8571)

- An information disclosure vulnerability exists in Microsoft Office due to improper handling of objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted document file, to disclose the contents of memory.
(CVE-2017-8572)

- A remote code execution vulnerability exists in Microsoft Outlook due to improper parsing of email messages. An unauthenticated, remote attacker can exploit this, with a specially crafted email message with a malicious attachment, to execute arbitrary code in the context of the current user. (CVE-2017-8663)
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.1432
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 99452
BID 99453
BID 100004
CVE CVE-2017-8571
CVE CVE-2017-8572
CVE CVE-2017-8663
MSKB 2956078
MSKB 3213643
MSKB 4011052
MSKB 4011078
XREF MSFT:MS17-2956078
XREF MSFT:MS17-3213643
XREF MSFT:MS17-4011052
XREF MSFT:MS17-4011078
Plugin Information
Published: 2017/07/28, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7187.5000
118928 - Security Updates for Outlook (November 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2018-8582)

- A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. (CVE-2018-8522, CVE-2018-8524, CVE-2018-8576)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461486
-KB4461529
-KB4461506
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.2039
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 105820
BID 105822
BID 105823
BID 105825
BID 105826
BID 105828
CVE CVE-2018-8522
CVE CVE-2018-8524
CVE CVE-2018-8558
CVE CVE-2018-8576
CVE CVE-2018-8579
CVE CVE-2018-8582
MSKB 4461486
MSKB 4461529
MSKB 4461506
XREF MSFT:MS18-4461486
XREF MSFT:MS18-4461529
XREF MSFT:MS18-4461506
Plugin Information
Published: 2018/11/13, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7224.5000
103752 - Security Updates for Outlook (October 2017)
-
Synopsis
The version of Outlook installed on the remote host is affected by multiple vulnerabilities.
Description
The version of Microsoft Outlook installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- An information disclosure vulnerability exists when Microsoft Outlook fails to establish a secure connection. An attacker who exploited the vulnerability could use it to obtain the email content of a user. The security update addresses the vulnerability by preventing Outlook from disclosing user email content.
(CVE-2017-11776)

- A security feature bypass vulnerability exists when Microsoft Office improperly handles objects in memory.
An attacker who successfully exploited the vulnerability could execute arbitrary commands. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince users to open the document file and interact with the document. The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory. (CVE-2017-11774)
See Also
Solution
Microsoft has released a set of patches for Outlook 2010, 2013, and 2016.
Risk Factor
Medium
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.8285
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.9 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
BID 101098
BID 101106
CVE CVE-2017-11774
CVE CVE-2017-11776
MSKB 4011178
MSKB 4011196
XREF MSFT:MS17-4011162
XREF MSFT:MS17-4011178
XREF MSFT:MS17-4011196
XREF IAVA:2017-A-0291-S
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Plugin Information
Published: 2017/10/10, Modified: 2023/02/17
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7189.5000
118014 - Security Updates for Outlook (October 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities including a remote code execution vulnerability requiring user interaction. See Microsoft Security Advisory ADV180026 for more information.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4092477
-KB4461440
-KB4227170
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
References
MSKB 4092477
MSKB 4461440
MSKB 4227170
XREF MSFT:MS18-4092477
XREF MSFT:MS18-4461440
XREF MSFT:MS18-4227170
Plugin Information
Published: 2018/10/09, Modified: 2022/06/10
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7214.5000
103456 - Security Updates for Outlook (September 2017)
-
Synopsis
The version of Outlook installed on the remote host is affected by multiple vulnerabilities.
Description
The version of Microsoft Outlook installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system to then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2017-0106)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted file. (CVE-2017-0204)

- A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system to then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2017-8506)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited this vulnerability could take control of an affected system.
(CVE-2017-8507)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. (CVE-2017-8508)

- A security feature bypass vulnerability exists when Microsoft Office Outlook improperly handles input.
An attacker who successfully exploited the vulnerability could execute arbitrary commands. (CVE-2017-8571)

- An information disclosure vulnerability exists when Microsoft Outlook fails to properly validate authentication requests. (CVE-2017-8572)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system.
(CVE-2017-8663)
See Also
Solution
Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3391
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.9 (CVSS2#E:U/RL:OF/RC:C)
References
BID 97413
BID 97458
BID 98811
BID 98827
BID 98828
BID 99452
BID 99453
BID 100004
CVE CVE-2017-0106
CVE CVE-2017-0204
CVE CVE-2017-8506
CVE CVE-2017-8507
CVE CVE-2017-8508
CVE CVE-2017-8571
CVE CVE-2017-8572
CVE CVE-2017-8663
MSKB 4011089
MSKB 4011110
MSKB 4011091
MSKB 4011090
XREF MSFT:MS17-4011089
XREF MSFT:MS17-4011110
XREF MSFT:MS17-4011091
XREF MSFT:MS17-4011090
Plugin Information
Published: 2017/09/25, Modified: 2019/11/12
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7187.5000
234220 - Security Updates for SQL Server Management Studio (April 2025)
-
Synopsis
The SQL Server Management Studio installation on the remote host is missing a security update.
Description
The SQL Server Management Studio installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- An elevation of privilege vulnerability. An attacker can exploit this to gain elevated privileges.
(CVE-2025-29803)
See Also
Solution
Microsoft has released SSMS version 20.2.1 to address this issue.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-29803
XREF IAVA:2025-B-0053
XREF CWE:427
Plugin Information
Published: 2025/04/11, Modified: 2025/09/17
Plugin Output

tcp/445/cifs


Path : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\IDE\
Installed version : 20.1.10.0
Fixed version : 20.2.37.0 (20.2.1)
99365 - Security and Quality Rollup for .NET Framework (April 2017)
-
Synopsis
The remote Windows host has a software framework installed that is affected by an arbitrary code execution vulnerability.
Description
The version of Microsoft .NET Framework installed on the remote Windows host is missing a security update. It is, therefore, affected by an arbitrary code execution vulnerability due to a failure to properly validate input before loading libraries. A local attacker can exploit this to execute arbitrary code with elevated privileges.
See Also
Solution
Microsoft has released a set of patches for Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.0 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.1751
CVSS v2.0 Base Score
7.2 (CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.6 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 97447
CVE CVE-2017-0160
MSKB 4014545
MSKB 4014546
MSKB 4014547
MSKB 4014548
MSKB 4014549
MSKB 4014550
MSKB 4014551
MSKB 4014552
MSKB 4014553
MSKB 4014555
MSKB 4014556
MSKB 4014557
MSKB 4014558
MSKB 4014559
MSKB 4014560
MSKB 4014561
MSKB 4014562
MSKB 4014563
MSKB 4014564
MSKB 4014565
MSKB 4014566
MSKB 4014567
MSKB 4014571
MSKB 4014572
MSKB 4014573
MSKB 4014574
MSKB 4015217
MSKB 4015219
MSKB 4015221
MSKB 4015583
XREF MSFT:MS17-4014545
XREF MSFT:MS17-4014546
XREF MSFT:MS17-4014547
XREF MSFT:MS17-4014548
XREF MSFT:MS17-4014549
XREF MSFT:MS17-4014550
XREF MSFT:MS17-4014551
XREF MSFT:MS17-4014552
XREF MSFT:MS17-4014553
XREF MSFT:MS17-4014555
XREF MSFT:MS17-4014556
XREF MSFT:MS17-4014557
XREF MSFT:MS17-4014558
XREF MSFT:MS17-4014559
XREF MSFT:MS17-4014560
XREF MSFT:MS17-4014561
XREF MSFT:MS17-4014562
XREF MSFT:MS17-4014563
XREF MSFT:MS17-4014564
XREF MSFT:MS17-4014565
XREF MSFT:MS17-4014566
XREF MSFT:MS17-4014567
XREF MSFT:MS17-4014571
XREF MSFT:MS17-4014572
XREF MSFT:MS17-4014573
XREF MSFT:MS17-4014574
XREF MSFT:MS17-4015217
XREF MSFT:MS17-4015219
XREF MSFT:MS17-4015221
XREF MSFT:MS17-4015583
Plugin Information
Published: 2017/04/14, Modified: 2025/12/25
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4015217

C:\Windows\Microsoft.NET\Framework\v2.0.50727\Wminet_utils.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8758

100056 - Security and Quality Rollup for .NET Framework (May 2017)
-
Synopsis
The remote Windows host has a software framework installed that is affected by a security feature bypass vulnerability.
Description
The version of Microsoft .NET Framework installed on the remote Windows host is missing a security update. It is, therefore, affected by a security bypass vulnerability in the Microsoft .NET Framework and .NET Core components due to a failure to completely validate certificates. An unauthenticated, remote attacker can exploit this to present a certificate that is marked invalid for a specific use, but the component uses it for that purpose, resulting in a bypass of the Enhanced Key Usage taggings.
See Also
Solution
Microsoft has released a set of patches for Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.5 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0109
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 98117
CVE CVE-2017-0248
MSKB 4016871
MSKB 4019108
MSKB 4019109
MSKB 4019110
MSKB 4019111
MSKB 4019112
MSKB 4019113
MSKB 4019114
MSKB 4019115
MSKB 4019472
MSKB 4019473
MSKB 4019474
XREF MSFT:MS17-4016871
XREF MSFT:MS17-4019108
XREF MSFT:MS17-4019109
XREF MSFT:MS17-4019110
XREF MSFT:MS17-4019111
XREF MSFT:MS17-4019112
XREF MSFT:MS17-4019113
XREF MSFT:MS17-4019114
XREF MSFT:MS17-4019115
XREF MSFT:MS17-4019472
XREF MSFT:MS17-4019473
XREF MSFT:MS17-4019474
Plugin Information
Published: 2017/05/09, Modified: 2019/11/13
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4019472

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8759

103137 - Security and Quality Rollup for .NET Framework (Sep 2017)
-
Synopsis
The remote Windows host has a software framework installed that is affected by a security feature bypass vulnerability.
Description
The .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input. An attacker who successfully exploited this vulnerability in software using the .NET framework could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
(CVE-2017-8759)
See Also
Solution
Microsoft has released a set of patches for Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.8
EPSS Score
0.9395
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
References
BID 100742
CVE CVE-2017-8759
MSKB 4041093
MSKB 4041083
MSKB 4041090
MSKB 4041084
MSKB 4041091
MSKB 4041085
MSKB 4041092
MSKB 4038781
MSKB 4038783
MSKB 4038782
MSKB 4038788
XREF MSFT:MS17-4041086
XREF MSFT:MS17-4041093
XREF MSFT:MS17-4041083
XREF MSFT:MS17-4041090
XREF MSFT:MS17-4041084
XREF MSFT:MS17-4041091
XREF MSFT:MS17-4041085
XREF MSFT:MS17-4041092
XREF MSFT:MS17-4038781
XREF MSFT:MS17-4038783
XREF MSFT:MS17-4038782
XREF MSFT:MS17-4038788
XREF CISA-KNOWN-EXPLOITED:2022/05/03
Exploitable With
CANVAS (true) Core Impact (true)
Plugin Information
Published: 2017/09/12, Modified: 2021/11/30
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4038782

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.runtime.remoting.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8771

276819 - Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803)
-
Synopsis
A Microsoft development toolset on the remote Windows host is affected by privilege escalation.
Description
In VSTA 2019 (prior 16.0.35907.0) and VSTA 2022 (prior to 17.0.35906.0), the software contains a vulnerability (CVE-2025-29803) that could allow remote or local attackers to execute arbitrary code or escalate privileges within the host application, potentially compromising systems that rely on VSTA for automation or extensibility.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.3 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0005
CVSS v2.0 Base Score
6.8 (CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C)
STIG Severity
I
References
CVE CVE-2025-29803
XREF IAVA:2025-A-0247
Plugin Information
Published: 2025/11/25, Modified: 2025/11/25
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Installed version : 16.0.31110
Fixed version : 16.0.35907.0
180174 - WinRAR < 6.23 RCE
-
Synopsis
The remote Windows host has an application installed which is affected by a remote code execution vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows.

The version of WinRAR installed on the remote host is affected by a an improper validation of user-supplied data, which can result in memory access past the end of an allocated buffer which can be exploited remotely and may allow attackers to execute code in the context of the current process.
See Also
Solution
Upgrade to WinRAR version 6.23 or later.
Risk Factor
High
CVSS v3.0 Base Score
7.8 (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
7.5 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.7
EPSS Score
0.9385
CVSS v2.0 Base Score
9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
8.1 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2023-38831
CVE CVE-2023-40477
XREF CISA-KNOWN-EXPLOITED:2023/09/14
XREF IAVA:2023-A-0436-S
Exploitable With
Core Impact (true) Metasploit (true)
Plugin Information
Published: 2023/08/24, Modified: 2024/05/03
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 6.23
192940 - WinRAR < 7.00 Multiple Vulnerabilities
-
Synopsis
The remote Windows host has an application installed which is affected by multiple vulnerabilities.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.00. It is, therefore, affected by multiple vulnerabilties:

- The vulnerability exists due to an error within the archive extraction functionality. A remote attacker can use a specially crafted archive to bypass the Mark-Of-The-Web protection mechanism and potentially compromise the affected system. (CVE-2024-30370)

- RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. (CVE-2024-36052)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.00 or later.
Risk Factor
Medium
CVSS v3.0 Base Score
7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.7 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0042
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.9 (CVSS2#E:POC/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2024-30370
CVE CVE-2024-36052
XREF IAVA:2024-A-0194-S
XREF IAVA:2024-A-0303-S
Plugin Information
Published: 2024/04/05, Modified: 2025/06/23
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.0
166555 - WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
-
Synopsis
The remote Windows host is potentially missing a mitigation for a remote code execution vulnerability.
Description
The remote system may be in a vulnerable state to CVE-2013-3900 due to a missing or misconfigured registry keys:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck An unauthenticated, remote attacker could exploit this, by sending specially crafted requests, to execute arbitrary code on an affected host.
See Also
Solution
Add and enable registry value EnableCertPaddingCheck:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck

Additionally, on 64 Bit OS systems, Add and enable registry value EnableCertPaddingCheck:

- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Risk Factor
High
CVSS v3.0 Base Score
8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
8.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
9.0
EPSS Score
0.7941
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
II
References
CVE CVE-2013-3900
XREF CISA-KNOWN-EXPLOITED:2022/07/10
XREF IAVA:2013-A-0227
Plugin Information
Published: 2022/10/26, Modified: 2025/12/17
Plugin Output

tcp/445/cifs



Nessus detected the following potentially insecure registry key configuration:
- Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.
- Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck is not present in the registry.

12085 - Apache Tomcat Default Files
-
Synopsis
The remote web server contains default files.
Description
The default error page, default index page, example JSPs and/or example servlets are installed on the remote Apache Tomcat server. These files should be removed as they may help an attacker uncover information about the remote Tomcat install or host itself.
See Also
Solution
Delete the default index page and remove the example JSP and servlets. Follow the Tomcat or OWASP instructions to replace or modify the default error page.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2004/03/02, Modified: 2024/09/03
Plugin Output

tcp/51528/www


The server is not configured to return a custom page in the event of a client requesting a non-existent resource.
This may result in a potential disclosure of sensitive information about the server to attackers.

12085 - Apache Tomcat Default Files
-
Synopsis
The remote web server contains default files.
Description
The default error page, default index page, example JSPs and/or example servlets are installed on the remote Apache Tomcat server. These files should be removed as they may help an attacker uncover information about the remote Tomcat install or host itself.
See Also
Solution
Delete the default index page and remove the example JSP and servlets. Follow the Tomcat or OWASP instructions to replace or modify the default error page.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2004/03/02, Modified: 2024/09/03
Plugin Output

tcp/51529/www


The server is not configured to return a custom page in the event of a client requesting a non-existent resource.
This may result in a potential disclosure of sensitive information about the server to attackers.

149390 - KB5003197: Windows 10 1607 / Windows Server 2016 Security Update (May 2021)
-
Synopsis
The remote host is missing one or more security updates.
Description
The remote Windows host is missing security updates. It is, therefore, affected by multiple vulnerabilities: Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released KB5003197 to address this issue.
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
8.9
EPSS Score
0.6391
CVSS v2.0 Base Score
7.6 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
6.6 (CVSS2#E:H/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-24587
CVE CVE-2020-24588
CVE CVE-2020-26144
CVE CVE-2021-26419
CVE CVE-2021-28455
CVE CVE-2021-28476
CVE CVE-2021-28479
CVE CVE-2021-31182
CVE CVE-2021-31184
CVE CVE-2021-31186
CVE CVE-2021-31187
CVE CVE-2021-31188
CVE CVE-2021-31193
CVE CVE-2021-31194
MSKB 5003197
XREF MSFT:MS21-5003197
XREF IAVA:2021-A-0223-S
XREF IAVA:2021-A-0222-S
Plugin Information
Published: 2021/05/11, Modified: 2024/11/28
Plugin Output

tcp/445/cifs


The remote host is missing one of the following rollup KBs :
- 5003197

- C:\Windows\system32\ntoskrnl.exe has not been patched.
Remote version : 10.0.14393.2273
Should be : 10.0.14393.4402
70852 - MS13-094: Vulnerability in Microsoft Outlook Could Allow Information Disclosure (2894514)
-
Synopsis
The version of Microsoft Outlook installed on the remote Windows host is affected by an information disclosure vulnerability.
Description
The Outlook component of Microsoft Office is affected by an information disclosure vulnerability due to a flaw in how Outlook parses S/MIME messages. It is possible for a remote attacker to exploit the vulnerability if a user opens or previews a specially crafted email in an affected version of Outlook.
See Also
Solution
Microsoft has released a set of patches for Office 2007, 2010, 2013 and 2013 RT.
Risk Factor
Medium
VPR Score
2.7
EPSS Score
0.122
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
References
BID 63603
CVE CVE-2013-3905
MSKB 2825644
MSKB 2837597
MSKB 2837618
XREF MSFT:MS13-094
Plugin Information
Published: 2013/11/13, Modified: 2019/11/27
Plugin Output

tcp/445/cifs



KB : 2837597
- C:\Program Files (x86)\Microsoft Office\Office14\\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Should be : 14.0.7109.5000
71321 - MS13-106: Vulnerability in a Microsoft Office Shared Component Could Allow Security Feature Bypass (2905238)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The remote Windows host is running a version of Microsoft Office that contains a shared component that is affected by a security feature bypass. Successful exploitation of the issue can allow an attacker to bypass the Address Space Layout Randomization (ASLR) security feature.
An attacker would need to entice a victim to visit a specially crafted web page with a browser capable of instantiating COM components in order to trigger the issue.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007 and 2010.
Risk Factor
Medium
VPR Score
4.2
EPSS Score
0.148
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.6 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
II
References
BID 64095
CVE CVE-2013-5057
MSKB 2850016
MSKB 2850022
XREF MSFT:MS13-106
XREF IAVB:2013-B-0135
Exploitable With
Core Impact (true)
Plugin Information
Published: 2013/12/11, Modified: 2018/11/15
Plugin Output

tcp/445/cifs



KB : 2850016
- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll has not been patched.
Remote version : 2.5.50727.4039
Should be : 5.70.51021.0
73983 - MS14-024: Vulnerability in a Microsoft Common Control Could Allow Security Feature Bypass (2961033)
-
Synopsis
The remote Windows host is affected by a security feature bypass vulnerability.
Description
The remote Windows host is running a version of Microsoft Office that contains a shared component (MSCOMCTL common controls library) that is affected by a security feature bypass. Successful exploitation of the issue could allow an attacker to bypass the Address Space Layout Randomization (ASLR) security feature. An attacker would need to entice a victim to visit a specially crafted web page with a browser capable of instantiating COM components in order to exploit the issue.
See Also
Solution
Microsoft has released a set of patches for Microsoft Office 2007, 2010, and 2013.
Risk Factor
Medium
VPR Score
5.9
EPSS Score
0.1293
CVSS v2.0 Base Score
6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS v2.0 Temporal Score
5.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
II
References
BID 67273
CVE CVE-2014-1809
MSKB 2961033
MSKB 2880508
MSKB 2880507
MSKB 2880502
MSKB 2817330
MSKB 2760272
MSKB 2880971
MSKB 2810073
MSKB 2596804
MSKB 2589288
XREF MSFT:MS14-024
XREF IAVB:2014-B-0057
Plugin Information
Published: 2014/05/14, Modified: 2019/11/26
Plugin Output

tcp/445/cifs



KB : 2810073
- C:\Windows\SysWOW64\mscomctl.ocx has not been patched.
Remote version : 6.1.98.18
Should be : 6.1.98.39
214532 - Oracle Java SE Multiple Vulnerabilities (January 2025 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities
Description
The 8u431, 11.0.26, 17.0.14, 20.3.16, 21.0.5, 21.3.12, 23.0.2, and perf versions of Java installed on the remote host are affected by multiple vulnerabilities as referenced in the January 2025 CPU advisory.

- Vulnerability in Oracle Java SE (component: Install (Sparkle)). The supported version that is affected is Oracle Java SE: 8u431. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Only applies to the macOS autoupdater. (CVE-2025-0509)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.26, 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM for JDK: 17.0.14, 21.0.5, 23.0.2; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2025-21502)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the January 2025 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
5.9 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
5.9
EPSS Score
0.0003
CVSS v2.0 Base Score
7.2 (CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2025-0509
CVE CVE-2025-21502
XREF IAVA:2025-A-0049-S
Plugin Information
Published: 2025/01/23, Modified: 2025/08/06
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.441 or greater
202704 - Oracle Java SE Multiple Vulnerabilities (July2024 CPU)
-
Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is affected by multiple vulnerabilities as referenced in the July 2024 CPU advisory:

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21147)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21145)

- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. (CVE-2024-21140)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Apply the appropriate patch according to the July 2024 Oracle Critical Patch Update advisory.
Risk Factor
High
CVSS v3.0 Base Score
4.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v3.0 Temporal Score
4.2 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
6.0
EPSS Score
0.0019
CVSS v2.0 Base Score
7.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N)
CVSS v2.0 Temporal Score
5.3 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
Plugin Information
Published: 2024/07/19, Modified: 2025/06/18
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Installed version : 8.0.401.10 / build 8.0.401
Fixed version : Upgrade to version 8.0.421 or greater
57608 - SMB Signing not required
-
Synopsis
Signing is not required on the remote SMB server.
Description
Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB server.
See Also
Solution
Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications (always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)
Plugin Information
Published: 2012/01/19, Modified: 2022/10/05
Plugin Output

tcp/445/cifs

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=SSL_Self_Signed_Fallback
|-Issuer : CN=SSL_Self_Signed_Fallback

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : CN=XHwakEyeSrv
|-Issuer : CN=XHwakEyeSrv

51192 - SSL Certificate Cannot Be Trusted
-
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :

- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.

- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.

- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.

If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2010/12/15, Modified: 2025/06/16
Plugin Output

tcp/51528/www


The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :

|-Subject : C=IN/ST=Maharashtra/L=Mumbai/O=LKP SECURITIES LIMITED/CN=www.lkp.net.in
|-Issuer : C=BE/O=GlobalSign nv-sa/CN=GlobalSign RSA OV SSL CA 2018

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/1433/mssql


The identities known by Nessus are :

10.113.99.73
10.195.58.173
10.20.30.61
172.17.100.73
xhwakeyesrv
172.17.100.73

The Common Name in the certificate is :

SSL_Self_Signed_Fallback

45411 - SSL Certificate with Wrong Hostname
-
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output

tcp/51528/www


The identities known by Nessus are :

10.113.99.73
10.195.58.173
10.20.30.61
172.17.100.73
xhwakeyesrv
172.17.100.73

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

65821 - SSL RC4 Cipher Suites Supported (Bar Mitzvah)
-
Synopsis
The remote service supports the use of the RC4 cipher.
Description
The remote host supports the use of RC4 in one or more cipher suites.
The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its randomness.

If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive the plaintext.
See Also
Solution
Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server support.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:U/RL:X/RC:C)
VPR Score
7.3
EPSS Score
0.9032
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:ND/RC:C)
References
BID 58796
BID 73684
CVE CVE-2013-2566
CVE CVE-2015-2808
Plugin Information
Published: 2013/04/05, Modified: 2025/05/09
Plugin Output

tcp/1433/mssql


List of RC4 cipher suites supported by the remote server :

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

65821 - SSL RC4 Cipher Suites Supported (Bar Mitzvah)
-
Synopsis
The remote service supports the use of the RC4 cipher.
Description
The remote host supports the use of RC4 in one or more cipher suites.
The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its randomness.

If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive the plaintext.
See Also
Solution
Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server support.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:U/RL:X/RC:C)
VPR Score
7.3
EPSS Score
0.9032
CVSS v2.0 Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
4.3 (CVSS2#E:U/RL:ND/RC:C)
References
BID 58796
BID 73684
CVE CVE-2013-2566
CVE CVE-2015-2808
Plugin Information
Published: 2013/04/05, Modified: 2025/05/09
Plugin Output

tcp/3389/msrdp


List of RC4 cipher suites supported by the remote server :

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/1433/mssql


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=SSL_Self_Signed_Fallback

57582 - SSL Self-Signed Certificate
-
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host.

Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output

tcp/3389/msrdp


The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :

|-Subject : CN=XHwakEyeSrv

141503 - Security Updates for Microsoft .NET Framework (October 2020)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.
(CVE-2020-16937)
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Medium
CVSS v3.0 Base Score
4.7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
4.1 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0389
CVSS v2.0 Base Score
4.0 (CVSS2#AV:L/AC:H/Au:N/C:C/I:N/A:N)
CVSS v2.0 Temporal Score
3.0 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2020-16937
MSKB 4578968
MSKB 4578969
MSKB 4578971
MSKB 4578972
MSKB 4578974
MSKB 4579976
MSKB 4579977
MSKB 4579978
MSKB 4579979
MSKB 4579980
MSKB 4580327
MSKB 4580328
MSKB 4580330
MSKB 4580346
MSKB 4580467
MSKB 4580468
MSKB 4580469
MSKB 4580470
XREF MSFT:MS20-4578968
XREF MSFT:MS20-4578969
XREF MSFT:MS20-4578971
XREF MSFT:MS20-4578972
XREF MSFT:MS20-4578974
XREF MSFT:MS20-4579976
XREF MSFT:MS20-4579977
XREF MSFT:MS20-4579978
XREF MSFT:MS20-4579979
XREF MSFT:MS20-4579980
XREF MSFT:MS20-4580327
XREF MSFT:MS20-4580328
XREF MSFT:MS20-4580330
XREF MSFT:MS20-4580346
XREF MSFT:MS20-4580467
XREF MSFT:MS20-4580468
XREF MSFT:MS20-4580469
XREF MSFT:MS20-4580470
XREF IAVA:2020-A-0456-S
XREF CEA-ID:CEA-2020-0126
Plugin Information
Published: 2020/10/19, Modified: 2022/12/05
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4571694

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.security.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8953

10_2020 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\system.security.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3701.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4580346

C:\Windows\Microsoft.NET\Framework\v2.0.50727\system.security.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8953

128742 - Security Updates for Microsoft .NET Framework (September 2019)
-
Synopsis
The Microsoft .NET Framework installation on the remote host is missing a security update.
Description
The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by an elevation of privilege vulnerability, which exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations. An attacker who successfully exploited this vulnerability could write files to folders that require higher privileges than what the attacker already has.
See Also
Solution
Microsoft has released security updates for Microsoft .NET Framework.
Risk Factor
Low
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.0046
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
1.6 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2019-1142
MSKB 4514355
MSKB 4514354
MSKB 4514357
MSKB 4514356
MSKB 4514359
MSKB 4514604
MSKB 4514603
MSKB 4514601
MSKB 4516068
MSKB 4514599
MSKB 4516044
MSKB 4516058
MSKB 4516070
MSKB 4516066
MSKB 4514598
XREF MSFT:MS19-4514355
XREF MSFT:MS19-4514354
XREF MSFT:MS19-4514357
XREF MSFT:MS19-4514356
XREF MSFT:MS19-4514359
XREF MSFT:MS19-4514604
XREF MSFT:MS19-4514603
XREF MSFT:MS19-4514601
XREF MSFT:MS19-4516068
XREF MSFT:MS19-4514599
XREF MSFT:MS19-4516044
XREF MSFT:MS19-4516058
XREF MSFT:MS19-4516070
XREF MSFT:MS19-4516066
XREF MSFT:MS19-4514598
XREF IAVA:2019-A-0339-S
Plugin Information
Published: 2019/09/12, Modified: 2021/06/03
Plugin Output

tcp/445/cifs


Microsoft .NET Framework 4.7.2
The remote host is missing one of the following rollup KBs :

Cumulative
- 4516044

C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8810

09_2019 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll has not been patched.
Remote version : 4.7.3062.0
Should be : 4.7.3460.0

Microsoft .NET Framework 3.5
The remote host is missing one of the following rollup KBs :

Cumulative
- 4516044

C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll has not been patched.
Remote version : 2.0.50727.8745
Should be : 2.0.50727.8810

147218 - Security Updates for Microsoft Office Products (March 2021)
-
Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
They are affected by a remote code execution vulnerability. An attacker can exploit this to bypass authentication and execute unauthorized arbitrary commands. (CVE-2021-24108, CVE-2021-27054, CVE-2021-27057, CVE-2021-27059)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4493228
-KB4493203
-KB4504703
-KB4493225
-KB4493200
-KB4493214
Risk Factor
High
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
CVSS v3.0 Temporal Score
6.0 (CVSS:3.0/E:F/RL:O/RC:C)
VPR Score
7.4
EPSS Score
0.0487
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS v2.0 Temporal Score
7.0 (CVSS2#E:F/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2021-24108
CVE CVE-2021-27054
CVE CVE-2021-27057
CVE CVE-2021-27059
MSKB 4493228
MSKB 4493203
MSKB 4504703
MSKB 4493225
MSKB 4493200
MSKB 4493214
XREF MSFT:MS21-4493228
XREF MSFT:MS21-4493203
XREF MSFT:MS21-4504703
XREF MSFT:MS21-4493225
XREF MSFT:MS21-4493200
XREF MSFT:MS21-4493214
XREF IAVA:2021-A-0132-S
XREF CISA-KNOWN-EXPLOITED:2021/11/17
Plugin Information
Published: 2021/03/09, Modified: 2025/10/31
Plugin Output

tcp/445/cifs



Product : Microsoft Office 2010 SP2
KB : 4504703
- C:\Program Files (x86)\Common Files\Microsoft Shared\Office14\mso.dll has not been patched.
Remote version : 14.0.6023.1000
Should be : 14.0.7266.5000

Product : Microsoft Office 2010 SP2
KB : 4493214
- C:\Program Files (x86)\Microsoft Office\Office14\graph.exe has not been patched.
Remote version : 14.0.6024.1000
Should be : 14.0.7266.5000
182956 - Security Updates for Microsoft SQL Server (October 2023)
-
Synopsis
The Microsoft SQL Server installation on the remote host is missing a security update.
Description
The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability:

- A Denial of Service vulnerability. An attacker could impact availability of the service resulting in Denial of Service (DoS) (CVE-2023-36728) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
See Also
Solution
Microsoft has released security updates for Microsoft SQL Server.
Risk Factor
Medium
CVSS v3.0 Base Score
5.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVSS v3.0 Temporal Score
4.8 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.0029
CVSS v2.0 Base Score
4.6 (CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C)
CVSS v2.0 Temporal Score
3.4 (CVSS2#E:U/RL:OF/RC:C)
STIG Severity
I
References
CVE CVE-2023-36728
MSKB 5029184
MSKB 5029185
MSKB 5029186
MSKB 5029187
MSKB 5029375
MSKB 5029376
MSKB 5029377
MSKB 5029378
MSKB 5029379
MSKB 5029503
XREF MSFT:MS23-5029184
XREF MSFT:MS23-5029185
XREF MSFT:MS23-5029186
XREF MSFT:MS23-5029187
XREF MSFT:MS23-5029375
XREF MSFT:MS23-5029376
XREF MSFT:MS23-5029377
XREF MSFT:MS23-5029378
XREF MSFT:MS23-5029379
XREF MSFT:MS23-5029503
XREF IAVA:2023-A-0541-S
Plugin Information
Published: 2023/10/12, Modified: 2024/01/12
Plugin Output

tcp/445/cifs



KB : 5029377
- C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe has not been patched.
Remote version : 2019.150.2000.5
Should be : 2019.150.2104.1

SQL Server Version : 15.0.2000.5 Standard Edition
SQL Server Instance : MSSQLSERVER
121027 - Security Updates for Outlook (January 2019)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages. An attacker who successfully exploited this vulnerability could gather information about the victim.
An attacker could exploit this vulnerability by sending a specially crafted email to the victim. The update addresses the vulnerability by correcting the way Microsoft Outlook handles these types of messages.
(CVE-2019-0559)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4461595
-KB4461601
-KB4461623

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2237
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2019-0559
MSKB 4461595
MSKB 4461601
MSKB 4461623
XREF MSFT:MS19-4461595
XREF MSFT:MS19-4461601
XREF MSFT:MS19-4461623
Plugin Information
Published: 2019/01/08, Modified: 2019/10/31
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7227.5000
110499 - Security Updates for Outlook (June 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is missing a security update.
Description
The Microsoft Outlook application installed on the remote host is missing a security update. It is, therefore, affected by the following vulnerability :

- An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly. An attacker who successfully exploited the vulnerability could send an email with hidden attachments that would be opened or executed once a victim clicks a link within the email. Note that this does not bypass attachment filters, so blocked attachments will still be excluded. (CVE-2018-8244)
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4022205
-KB4022169
-KB4022160
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
3.6
EPSS Score
0.104
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
CVE CVE-2018-8244
MSKB 4022205
MSKB 4022169
MSKB 4022160
XREF MSFT:MS18-4022205
XREF MSFT:MS18-4022169
XREF MSFT:MS18-4022160
Plugin Information
Published: 2018/06/12, Modified: 2019/11/04
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7210.5000
112116 - Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Rogue System Register Read (RSRE), Speculative Store Bypass (SSB), L1 Terminal Fault (L1TF), and Branch Target Injection vulnerabilities.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Medium
CVSS v3.0 Base Score
6.4 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N)
CVSS v3.0 Temporal Score
5.8 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.7
EPSS Score
0.3909
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:POC/RL:OF/RC:C)
References
BID 104228
BID 104232
BID 105080
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3640
CVE CVE-2018-3646
MSKB 4346084
MSKB 4346085
MSKB 4346086
MSKB 4346087
MSKB 4346088
XREF MSFT:MS18-4346084
XREF MSFT:MS18-4346085
XREF MSFT:MS18-4346086
XREF MSFT:MS18-4346087
XREF MSFT:MS18-4346088
Plugin Information
Published: 2018/08/24, Modified: 2025/03/26
Plugin Output

tcp/445/cifs



KB : 4346087
- C:\Windows\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2453
121035 - Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Spectre Variant 2 (CVE-2017-5715: Branch Target Injection) vulnerability.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Low
CVSS v3.0 Base Score
5.6 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.6
EPSS Score
0.9159
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102376
CVE CVE-2017-5715
MSKB 4090007
MSKB 4091663
MSKB 4091664
MSKB 4091666
MSKB 4100347
XREF MSFT:MS19-4090007
XREF MSFT:MS19-4091663
XREF MSFT:MS19-4091664
XREF MSFT:MS19-4091666
XREF MSFT:MS19-4100347
Plugin Information
Published: 2019/01/09, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



KB : 4091664
- C:\Windows\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2544
119239 - Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)
-
Synopsis
The remote Windows host is missing a microcode update.
Description
The remote Windows host is missing a security update. It is, therefore, missing microcode updates to address Spectre Variant 2 (CVE-2017-5715: Branch Target Injection) vulnerability.
See Also
Solution
Microsoft has released security updates for Windows 10 and Windows Server 2016.
Risk Factor
Low
CVSS v3.0 Base Score
5.6 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.4 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.6
EPSS Score
0.9159
CVSS v2.0 Base Score
1.9 (CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
1.7 (CVSS2#E:H/RL:OF/RC:C)
References
CVE CVE-2017-5715
MSKB 4091664
XREF MSFT:MS18-4091664
Plugin Information
Published: 2018/11/27, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



KB : 4091664
- C:\Windows\system32\mcupdate_genuineintel.dll has not been patched.
Remote version : 10.0.14393.0
Should be : 10.0.14393.2516

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/1433/mssql

TLSv1 is enabled and the server supports at least one cipher.

104743 - TLS Version 1.0 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.

As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.

PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.
See Also
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1 is enabled and the server supports at least one cipher.

157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/1433/mssql

TLSv1.1 is enabled and the server supports at least one cipher.

157288 - TLS Version 1.1 Deprecated Protocol
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVSS v2.0 Base Score
6.1 (CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N)
References
XREF CWE:327
Plugin Information
Published: 2022/04/04, Modified: 2024/05/14
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.
58453 - Terminal Services Doesn't Use Network Level Authentication (NLA) Only
-
Synopsis
The remote Terminal Services doesn't use Network Level Authentication only.
Description
The remote Terminal Services is not configured to use Network Level Authentication (NLA) only. NLA uses the Credential Security Support Provider (CredSSP) protocol to perform strong server authentication either through TLS/SSL or Kerberos mechanisms, which protect against man-in-the-middle attacks. In addition to improving authentication, NLA also helps protect the remote computer from malicious users and software by completing user authentication before a full RDP connection is established.
See Also
Solution
Enable Network Level Authentication (NLA) on the remote RDP server. This is generally done on the 'Remote' tab of the 'System' settings on Windows.
Risk Factor
Medium
CVSS v3.0 Base Score
4.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
Plugin Information
Published: 2012/03/23, Modified: 2025/09/29
Plugin Output

tcp/3389/msrdp

Nessus was able to negotiate non-NLA (Network Level Authentication) security.

234002 - WinRAR < 7.11 Mark of the Web Bypass (CVE-2025-31334)
-
Synopsis
The remote Windows host has an application installed which is affected by a mark of the web bypass vulnerability.
Description
The remote host is running WinRAR, an archive manager for Windows, whose reported version is prior to 7.11. It is, therefore, affected by a vulnerability:

- Issue that bypasses the 'Mark of the Web' security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. (CVE-2025-31334)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
Solution
Upgrade to WinRAR version 7.11 or later.
Risk Factor
High
CVSS v3.0 Base Score
6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
VPR Score
6.7
EPSS Score
0.0007
CVSS v2.0 Base Score
8.5 (CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
STIG Severity
II
References
CVE CVE-2025-31334
XREF IAVA:2025-A-0227
Plugin Information
Published: 2025/04/08, Modified: 2025/04/11
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Installed version : 5.90.0.0
Fixed version : 7.11
136946 - Windows 10 / Windows Server 2016 September 2017 Information Disclosure Vulnerability (CVE-2017-8529)
-
Synopsis
The remote Windows host is affected by an information disclosure vulnerability.
Description
The remote Windows host is missing a security update or a registry setting required to enable protections for CVE-2017-8529. It is, therefore, affected by an information disclosure vulnerability:

- An information disclosure vulnerability exists when affected Microsoft scripting engines do not properly handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability.
See Also
Solution
Refer to the Microsoft CVE article for additional information.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
5.7 (CVSS:3.0/E:U/RL:O/RC:C)
VPR Score
4.4
EPSS Score
0.2763
CVSS v2.0 Base Score
4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS v2.0 Temporal Score
3.2 (CVSS2#E:U/RL:OF/RC:C)
References
BID 98953
CVE CVE-2017-8529
MSKB 4038781
MSKB 4038783
MSKB 4038782
MSKB 4038788
XREF MSFT:MS17-4038781
XREF MSFT:MS17-4038783
XREF MSFT:MS17-4038782
XREF MSFT:MS17-4038788
Plugin Information
Published: 2020/05/28, Modified: 2024/06/17
Plugin Output

tcp/445/cifs



The following registry key is required to enable the fix for CVE-2017-8529 and is missing.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX\iexplore.exe

The following registry key is required to enable the fix for CVE-2017-8529 and is missing.
HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX\iexplore.exe
132101 - Windows Speculative Execution Configuration Check
-
Synopsis
The remote host has not properly mitigated a series of speculative execution vulnerabilities.
Description
The remote host has not properly mitigated a series of known speculative execution vulnerabilities. It, therefore, may be affected by :
- Branch Target Injection (BTI) (CVE-2017-5715)
- Bounds Check Bypass (BCB) (CVE-2017-5753)
- Rogue Data Cache Load (RDCL) (CVE-2017-5754)
- Rogue System Register Read (RSRE) (CVE-2018-3640)
- Speculative Store Bypass (SSB) (CVE-2018-3639)
- L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)
- Microarchitectural Data Sampling Uncacheable Memory (MDSUM) (CVE-2019-11091)
- Microarchitectural Store Buffer Data Sampling (MSBDS) (CVE-2018-12126)
- Microarchitectural Load Port Data Sampling (MLPDS) (CVE-2018-12127)
- Microarchitectural Fill Buffer Data Sampling (MFBDS) (CVE-2018-12130)
- TSX Asynchronous Abort (TAA) (CVE-2019-11135)
- Intel Branch History Injection (BHI) (CVE-2022-0001)
See Also
Solution
Apply vendor recommended settings.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
CVSS v3.0 Temporal Score
6.2 (CVSS:3.0/E:H/RL:O/RC:C)
VPR Score
7.9
EPSS Score
0.9433
CVSS v2.0 Base Score
5.4 (CVSS2#AV:L/AC:M/Au:N/C:C/I:P/A:N)
CVSS v2.0 Temporal Score
4.7 (CVSS2#E:H/RL:OF/RC:C)
References
BID 102371
BID 102378
BID 104232
BID 105080
BID 108330
CVE CVE-2017-5715
CVE CVE-2017-5753
CVE CVE-2017-5754
CVE CVE-2018-3615
CVE CVE-2018-3620
CVE CVE-2018-3639
CVE CVE-2018-3646
CVE CVE-2018-12126
CVE CVE-2018-12127
CVE CVE-2018-12130
CVE CVE-2019-11135
CVE CVE-2022-0001
XREF CEA-ID:CEA-2019-0547
XREF CEA-ID:CEA-2019-0324
Exploitable With
CANVAS (true)
Plugin Information
Published: 2019/12/18, Modified: 2025/08/27
Plugin Output

tcp/445/cifs

Current Settings:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: Not Set
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: Not Set

-----------------------------------

Recommended Settings 1:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00000048 (72)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading enabled.

-----------------------------------

Recommended Settings 2:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00002048 (8264)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 3:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00802048 (8396872)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading disabled.

-----------------------------------

Recommended Settings 4:
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverrideMask: 0x00000003 (3)
- SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\
FeatureSettingsOverride: 0x00800048 (8388680)
CVEs Covered:
CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2018-3615, CVE-2018-3620,
CVE-2018-3639, CVE-2018-3646, CVE-2018-11091, CVE-2018-12126, CVE-2018-12127,
CVE-2018-12130, CVE-2019-11135, CVE-2022-0001
Note: Hyper-Threading enabled.

10114 - ICMP Timestamp Request Remote Date Disclosure
-
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.

Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
CVSS v2.0 Base Score
2.1 (CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N)
References
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output

icmp/0

This host returns non-standard timestamps (high bit is set)
The ICMP timestamps might be in little endian format (not in network format)
The difference between the local and remote clocks is 80 seconds.

111756 - Security Updates for Outlook (August 2018)
-
Synopsis
The Microsoft Outlook application installed on the remote host is affected by multiple vulnerabilities.
Description
The Microsoft Outlook application installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities.
See Also
Solution
Microsoft has released the following security updates to address this issue:
-KB4032222
-KB4032235
-KB4032240
Risk Factor
Low
References
MSKB 4032222
MSKB 4032235
MSKB 4032240
XREF MSFT:MS18-4032222
XREF MSFT:MS18-4032235
XREF MSFT:MS18-4032240
Plugin Information
Published: 2018/08/15, Modified: 2018/08/15
Plugin Output

tcp/445/cifs



Product : Outlook 2010
- C:\Program Files (x86)\Microsoft Office\Office14\Outlook.exe has not been patched.
Remote version : 14.0.6025.1000
Fixed version : 14.0.7212.5000

46180 - Additional DNS Hostnames
-
Synopsis
Nessus has detected potential virtual hosts.
Description
Hostnames different from the current hostname have been collected by miscellaneous plugins. Nessus has generated a list of hostnames that point to the remote host. Note that these are only the alternate hostnames for vhosts discovered on a web server.

Different web servers may be hosted on name-based virtual hosts.
See Also
Solution
If you want to test them, re-scan using the special vhost syntax, such as :

www.example.com[192.0.32.10]
Risk Factor
None
Plugin Information
Published: 2010/04/29, Modified: 2022/08/15
Plugin Output

tcp/0

The following hostnames point to the remote host :
- xhwakeyesrv

16193 - Antivirus Software Check
-
Synopsis
An antivirus application is installed on the remote host.
Description
An antivirus application is installed on the remote host, and its engine and virus definitions are up to date.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/01/18, Modified: 2025/05/27
Plugin Output

tcp/445/cifs


Kaspersky :
Kaspersky Anti-Virus is installed on the remote host :

Product name : Kaspersky Endpoint Security for Windows
Version : 21.15.8.493
Installation path : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0
Virus signatures : 01/09/2026

156001 - Apache Log4j JAR Detection (Windows)
-
Synopsis
Apache Log4j is installed on the remote Windows host.
Description
One or more instances of Apache Log4j, a logging API, are installed on the remote Windows Host.

- Powershell version 5 or greater is required for this plugin.

- If the 'Perform thorough tests' setting is enabled, this plugin will inspect the manifest and properties files of the detected Java archive files.

- The plugin timeout can be set to a custom value other than the plugin's default of 60 minutes via the 'timeout.156001' scanner setting in Nessus 8.15.1 or later.

Please see https://docs.tenable.com/nessus/Content/SettingsAdvanced.htm#Custom for more information.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVA:0001-A-0650
XREF IAVT:0001-T-0941
Plugin Information
Published: 2021/12/10, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Apache Log4j:

Path : C:\Program Files\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Version : 1.2.17
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

Path : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Extensions\Common\Jars\log4j-1.2.17.jar
Version : 1.2.17
JMSAppender.class association : Found
JdbcAppender.class association : Found
JndiLookup.class association : Not Found
Method : log4j-core file search

406 Jar files successfully inspected.

39446 - Apache Tomcat Detection
-
Synopsis
The remote web server is an Apache Tomcat server.
Description
Nessus was able to detect a remote Apache Tomcat web server.

NOTE: When paranoia levels are elevated, this plugin will also consider versions obtained from responses with non-200 HTTP status codes.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2009/06/18, Modified: 2025/05/15
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/
Version : 9.0.104
backported : 0
source : Apache Tomcat/9.0.104

39446 - Apache Tomcat Detection
-
Synopsis
The remote web server is an Apache Tomcat server.
Description
Nessus was able to detect a remote Apache Tomcat web server.

NOTE: When paranoia levels are elevated, this plugin will also consider versions obtained from responses with non-200 HTTP status codes.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2009/06/18, Modified: 2025/05/15
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/
Version : 9.0.104
backported : 0
source : Apache Tomcat/9.0.104

130590 - Apache Tomcat Installed (Windows)
-
Synopsis
Apache Tomcat is installed on the remote Windows host.
Description
Apache Tomcat, a web server, was found on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2019/11/06, Modified: 2025/12/18
Plugin Output

tcp/0


Path : D:\XTPL\Tomcat\
Version : 9.0.89
Product : Apache Tomcat
141263 - Apache Tomcat Site Enumeration
-
Synopsis
The remote host is hosting websites using Apache Tomcat.
Description
Domain names and IP addresses from Apache Tomcat configuration file were retrieved from the remote host. Apache Tomcat is a webserver environment written in Java.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/07, Modified: 2025/10/08
Plugin Output

tcp/0

Following hostnames and connectors are present in D:\XTPL\Tomcat\conf\server.xml Tomcat config file:
+ Hostnames:
- localhost

+ Connectors:
- IP: *, port: 51527, protocol: HTTP/1.1
- IP: *, port: 443, protocol: HTTP/1.1
92415 - Application Compatibility Cache
-
Synopsis
Nessus was able to gather application compatibility settings on the remote host.
Description
Nessus was able to generate a report on the application compatibility cache on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Application compatibility cache report attached.
34097 - BIOS Info (SMB)
-
Synopsis
BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's SMB interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/08, Modified: 2024/06/11
Plugin Output

tcp/0


Version : P71
Release date : 20150701000000.000000+000
Secure boot : disabled
34096 - BIOS Info (WMI)
-
Synopsis
The BIOS info could be read.
Description
It is possible to get information about the BIOS via the host's WMI interface.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/05, Modified: 2025/12/15
Plugin Output

tcp/0


Vendor : HP
Version : P71
Release date : 20150701000000.000000+000
UUID : 30343536-3138-4753-4834-33374E5F4458
Secure boot : disabled
92416 - BagMRU Folder History
-
Synopsis
Nessus was able to enumerate folders that were opened in Windows Explorer.
Description
Nessus was able to enumerate folders that were opened in Windows Explorer. Microsoft Windows maintains folder settings using a registry key known as shellbags or BagMRU. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

BagMRU report attached.

96533 - Chrome Browser Extension Enumeration
-
Synopsis
One or more Chrome browser extensions are installed on the remote host.
Description
Nessus was able to enumerate Chrome browser extensions installed on the remote host.
See Also
Solution
Make sure that the use and configuration of these extensions comply with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2017/01/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


User : Administrator
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.99.1
Update Date : Jan. 7, 2026 at 01:41:26 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.99.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 7, 2026 at 01:41:26 GMT
Path : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

User : LKPAdmin
|- Browser : Chrome
|- Add-on information :

Name : Google Docs Offline
Description : Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.
Version : 1.89.1
Update Date : Jan. 9, 2026 at 19:35:06 GMT
Path : C:\Users\LKPAdmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.89.1_0

Name : Chrome Web Store Payments
Description : Chrome Web Store Payments
Version : 1.0.0.6
Update Date : Jan. 9, 2026 at 19:35:06 GMT
Path : C:\Users\LKPAdmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0

45590 - Common Platform Enumeration (CPE)
-
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host.

Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/09/29
Plugin Output

tcp/0


The remote operating system matched the following CPE :

cpe:/o:microsoft:windows_server_2016:10.0.14393.2273:-:~~datacenter~~x64~ -> Microsoft Windows Server 2016

Following application CPE's matched on the remote system :

cpe:/a:apache:log4j:1.2.17 -> Apache Software Foundation log4j
cpe:/a:apache:tomcat:9.0.104 -> Apache Software Foundation Tomcat
cpe:/a:apache:tomcat:9.0.89 -> Apache Software Foundation Tomcat
cpe:/a:google:chrome:143.0.7499.170 -> Google Chrome
cpe:/a:kaspersky:kaspersky_anti-virus:21.15.8.493 -> Kaspersky Anti-virus
cpe:/a:microsoft:.net_framework:2.0.50727 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.0 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:3.5 -> Microsoft .NET Framework
cpe:/a:microsoft:.net_framework:4.7.2 -> Microsoft .NET Framework
cpe:/a:microsoft:excel:14.0.6024.1000:1 -> Microsoft Excel
cpe:/a:microsoft:excelcnv:14.0.6024.1000:1
cpe:/a:microsoft:ie:11.2273.14393.0 -> Microsoft Internet Explorer
cpe:/a:microsoft:iis:10.0 -> Microsoft IIS
cpe:/a:microsoft:internet_explorer:11.0.14393.2273 -> Microsoft Internet Explorer
cpe:/a:microsoft:internet_information_services:10.0.14393.0 -> Microsoft Internet Information Server (IIS) -
cpe:/a:microsoft:office:2010:1 -> Microsoft Office
cpe:/a:microsoft:office_compatibility_pack -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.4762.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:office_compatibility_pack:14.0.6024.1000 -> Microsoft Office Compatibility Pack Service Pack 2
cpe:/a:microsoft:onenote:14.0.6022.1000 -> Microsoft OneNote
cpe:/a:microsoft:onenote:14.0.6022.1000:0 -> Microsoft OneNote
cpe:/a:microsoft:outlook:14.0.6025.1000:1 -> Microsoft Outlook
cpe:/a:microsoft:powerpoint:14.0.6026.1000:1 -> Microsoft PowerPoint
cpe:/a:microsoft:publisher:14.0.6026.1000:1 -> Microsoft Publisher
cpe:/a:microsoft:remote_desktop_connection:10.0.14393.2273 -> Microsoft Remote Desktop Connection
cpe:/a:microsoft:sql_server:13.0.5026.0 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.2000.0 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server:15.0.2000.5 -> Microsoft SQLServer
cpe:/a:microsoft:sql_server_management_studio:20.1.10.0 -> Microsoft SQL Server Management Studio
cpe:/a:microsoft:visual_studio_tools_for_applications:15.0.27520
cpe:/a:microsoft:visual_studio_tools_for_applications:16.0.31110
cpe:/a:microsoft:word:14.0.6024.1000:1 -> Microsoft Word
cpe:/a:microsoft:wordcnv:14.0.4762.1000:0
cpe:/a:notepad-plus-plus:notepad%2b%2b:8.6.6.0 -> notepad-plus-plus Notepad++
cpe:/a:oracle:jre:8.0.401 -> Oracle JRE
cpe:/a:oracle:jre:8.0.401.10 -> Oracle JRE
cpe:/a:postman:postman:11.69.2 -> Postman
cpe:/a:rarlab:winrar:5.90.0.0 -> RARLAB WinRAR
cpe:/a:smartbedded:meteobridge_firmware
x-cpe:/a:microsoft:odbc_driver_for_sql_server:13.2.5026.0
x-cpe:/a:microsoft:odbc_driver_for_sql_server:17.10.6.1
x-cpe:/a:microsoft:ole_db_driver_for_sql_server:18.7.2.0
24270 - Computer Manufacturer Information (WMI)
-
Synopsis
It is possible to obtain the name of the remote computer manufacturer.
Description
By making certain WMI queries, it is possible to obtain the model of the remote computer as well as the name of its manufacturer and its serial number.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/02, Modified: 2025/12/15
Plugin Output

tcp/0


Computer Manufacturer : HP
Computer Model : ProLiant DL360p Gen8
Computer SerialNumber : SGH437N_DX
Computer Type : Rack Mount Chassis

Computer Physical CPU's : 2
Computer Logical CPU's : 24
CPU0
Architecture : x64
Physical Cores: 6
Logical Cores : 12
CPU1
Architecture : x64
Physical Cores: 6
Logical Cores : 12

Computer Memory : 32733 MB

Form Factor: DIMM
Type : Unknown Code (24)
Capacity : 16384 MB

Form Factor: DIMM
Type : Unknown Code (24)
Capacity : 16384 MB

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/135/epmap


The following DCERPC services are available locally :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc08F860

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WindowsShutdown

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc08F860

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-52a210e485cf4667b4

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 237d4604-8af5-4c1b-8442-c05cacefd56f
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : OLE8554A875961F72615F6B312B7B57

Object UUID : 237d4604-8af5-4c1b-8442-c05cacefd56f
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-00541db5658f7298f0

Object UUID : 5252504b-4950-534e-84e2-025d80260000
UUID : 9b3e3722-843a-71fe-4b50-525250494453, version 17.200
Description : Unknown RPC service
Annotation : PRRUniversal#88DF2DBA91A2A0D1:9856
Type : Local RPC service
Named pipe : PRRUniversal#88DF2DBA91A2A0D1:9856

Object UUID : 5252504b-4950-534e-2e23-5c66c4260000
UUID : 9b3e3722-d604-9539-4b50-525250494453, version 17.200
Description : Unknown RPC service
Annotation : PRRUniversal#92386E809A0814EB:9924
Type : Local RPC service
Named pipe : PRRUniversal#92386E809A0814EB:9924

Object UUID : 5252504b-4950-534e-6b9c-da04f4230000
UUID : 9b3e3722-4402-a71e-4b50-525250494453, version 17.200
Description : Unknown RPC service
Annotation : PRRUniversal#30B6EB822FE382D5:9204
Type : Local RPC service
Named pipe : PRRUniversal#30B6EB822FE382D5:9204

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9435cc56-1d9c-4924-ac7d-b60a2c3520e1, version 1.0
Description : Unknown RPC service
Annotation : SPPSVC Default RPC Interface
Type : Local RPC service
Named pipe : SPPCTransportEndpoint-00001

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED197E880693B4849A6F90B576682

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : d2716e94-25cb-4820-bc15-537866578562, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6a486c338932bc302a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED197E880693B4849A6F90B576682

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6a486c338932bc302a

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLED197E880693B4849A6F90B576682

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 923c9623-db7f-4b34-9e6d-e86580f8ca2a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-6a486c338932bc302a

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3ECC392A14DF624C7EC1C7531A47

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 8ec21e98-b5ce-4916-a3d6-449fa428a007, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-63f430568f438e2931

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3ECC392A14DF624C7EC1C7531A47

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : 0fc77b1a-95d8-4a2e-a0c0-cff54237462b, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-63f430568f438e2931

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE3ECC392A14DF624C7EC1C7531A47

Object UUID : 00000002-0000-0000-0000-000000000000
UUID : b1ef227e-dfa5-421e-82bb-67a6a129c496, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-63f430568f438e2931

Object UUID : 5252504b-4950-534e-a6f0-390c3c200000
UUID : 9b3e3722-e809-121a-4b50-525250494453, version 35.114
Description : Unknown RPC service
Annotation : PRRUniversal#38164D10198667EC:8252
Type : Local RPC service
Named pipe : PRRUniversal#38164D10198667EC:8252

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:8252

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#38164D10198667EC:8252

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:8252

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#38164D10198667EC:8252

Object UUID : 0320773c-0000-0000-a6f0-390c3c200000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:8252

Object UUID : 0320773c-0000-0000-a6f0-390c3c200000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#38164D10198667EC:8252

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000002
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0C6F962

Object UUID : 52ef130c-08fd-4388-86b3-6edf00000002
UUID : 12e65dd8-887f-41ef-91bf-8d816c42c2e7, version 1.0
Description : Unknown RPC service
Annotation : Secure Desktop LRPC interface
Type : Local RPC service
Named pipe : WMsgKRpc0C6F962

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4b112204-0e19-11d3-b42b-0000f81feb9f, version 1.0
Description : SSDP service
Windows process : unknow
Type : Local RPC service
Named pipe : LRPC-e639a7f699665e29c5

Object UUID : 5252504b-4950-534e-d5c3-35b2941e0000
UUID : 9b3e3722-75b1-906c-4b50-525250494453, version 35.114
Description : Unknown RPC service
Annotation : PRRUniversal#DE12203E16083E4B:7828
Type : Local RPC service
Named pipe : PRRUniversal#DE12203E16083E4B:7828

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:7828

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#DE12203E16083E4B:7828

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:7828

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#DE12203E16083E4B:7828

Object UUID : 08c7cd0c-0000-0000-d5c3-35b2941e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:7828

Object UUID : 08c7cd0c-0000-0000-d5c3-35b2941e0000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#DE12203E16083E4B:7828

Object UUID : f48cc7d6-28bc-4b6d-a826-2281173d60cb
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-866d45e51d69388fc3

Object UUID : 1b8214c8-6f99-4c4d-a4b1-189591ac4879
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-866d45e51d69388fc3

Object UUID : b056b400-f538-4b51-8707-10e4cf4156b2
UUID : 906b0ce0-c70b-1067-b317-00dd010662da, version 1.0
Description : Distributed Transaction Coordinator
Windows process : msdtc.exe
Type : Local RPC service
Named pipe : LRPC-866d45e51d69388fc3

Object UUID : 5252504b-4950-534e-cbe9-b816b0090000
UUID : 9b3e3722-6918-d7b0-4b50-525250494453, version 35.114
Description : Unknown RPC service
Annotation : PRRUniversal#42954634892A26AA:2480
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-fb3c-0007-4b50-525250524944
UUID : 9b3e3722-d801-7233-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PR_REMOTE_MANAGER_PROP
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-e72a-000f-4b50-525250524944
UUID : 9b3e3722-e474-f035-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpnPRAGUE_REMOTE_API
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 06b80f90-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 06b80f90-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-abb6-0007-4b50-525250524944
UUID : 9b3e3722-7551-7dee-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTEMPFILE_MEMMANAGER
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 00000000-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 00000000-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-bab3-e001-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : ai_loader_remote_object
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 067a5cd4-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 067a5cd4-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-c75c-28ad-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : PRRoot
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-8790-000c-4b50-525250524944
UUID : 9b3e3722-1441-c93d-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_TYPE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-a517-000d-4b50-525250524944
UUID : 9b3e3722-f9a8-d5cb-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_PROFILE_NAME
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-b19c-0002-4b50-525250524944
UUID : 9b3e3722-050c-2b49-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTASK_MANAGER_TASK_ID
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-1931-0005-4b50-525250524944
UUID : 9b3e3722-a39b-5baa-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_HTTP_REQ
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-4d95-0005-4b50-525250524944
UUID : 9b3e3722-f7aa-5ba3-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_HTTP_RSP
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-b87a-0007-4b50-525250524944
UUID : 9b3e3722-86c2-73eb-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MESSAGE_IS_INCOMING
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-5916-0003-4b50-525250524944
UUID : 9b3e3722-0276-35b6-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MESSAGE_CHECK_ONLY
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-20c7-000f-4b50-525250524944
UUID : 9b3e3722-c49b-fe45-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : PROTOCOL_TYPE
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-c384-0000-4b50-525250524944
UUID : 9b3e3722-6122-0a2a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_VIRTUAL_OBJECT_NAME
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-7401-0008-4b50-525250524944
UUID : 9b3e3722-62c7-816c-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npUserContext
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-0568-0001-4b50-525250524944
UUID : 9b3e3722-1d09-1186-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npAVS_SCAN_AREA_ID
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-618e-000d-4b50-525250524944
UUID : 9b3e3722-7819-d199-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : antimalware.am_core_dll.registered
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-4dfb-000b-4b50-525250524944
UUID : 9b3e3722-56be-b1b4-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npSCAN_OBJECT_CONTEXT
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-5c94-000c-4b50-525250524944
UUID : 9b3e3722-7dc3-c215-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_READONLY_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-66bb-0002-4b50-525250524944
UUID : 9b3e3722-b130-2d78-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-0726-0007-4b50-525250524944
UUID : 9b3e3722-dfbb-7d89-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-21ab-0008-4b50-525250524944
UUID : 9b3e3722-da96-8fb3-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npENGINE_INTEGRAL_PARENT_IO
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-554f-0006-4b50-525250524944
UUID : 9b3e3722-3fdc-66a9-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npOBJECT_STARTUP
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-ae59-0004-4b50-525250524944
UUID : 9b3e3722-49dd-4e78-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : antimalware.oas.PenderPtr
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-e77b-0006-4b50-525250524944
UUID : 9b3e3722-d7d6-630a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : native file io object is a stream really
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-54e6-0005-4b50-525250524944
UUID : 9b3e3722-97cf-5c32-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : native file io object streams
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-c572-000b-4b50-525250524944
UUID : 9b3e3722-7d85-bb8f-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npTM_PROFILE
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-2be7-0004-4b50-525250524944
UUID : 9b3e3722-2175-40a9-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : cpTEMPFILE_SYSCACHED
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 075ddef8-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 075ddef8-0000-0000-cbe9-b816b0090000
UUID : 9b3e3722-b8eb-3e0b-4b50-52524f424a53, version 35.114
Description : Unknown RPC service
Annotation : TaskManager
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-aa75-0009-4b50-525250524944
UUID : 9b3e3722-b9de-913a-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : DEFER_THREAD_INIT
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-1e7b-0004-4b50-525250524944
UUID : 9b3e3722-6afd-4748-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MAILER_PID
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-487b-0006-4b50-525250524944
UUID : 9b3e3722-2a49-6623-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : npMESSAGE_IS_COMPLETE
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-cf60-000f-4b50-525250524944
UUID : 9b3e3722-93c9-f5ca-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : NO_NEED_TREATMENT
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRNameService:2480

Object UUID : 9b3e3722-7820-0006-4b50-525250524944
UUID : 9b3e3722-9839-6e01-4b50-525250524f50, version 35.114
Description : Unknown RPC service
Annotation : MAILER_TID
Type : Local RPC service
Named pipe : PRRUniversal#42954634892A26AA:2480

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4c9dbf19-d39e-4bb9-90ee-8f7179b20283, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f5c6feb00960a6ffc7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e38f5360-8572-473e-b696-1b46873beeab, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-f5c6feb00960a6ffc7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 98716d03-89ac-44c7-bb8c-285824e51c4a, version 1.0
Description : Unknown RPC service
Annotation : XactSrv service
Type : Local RPC service
Named pipe : LRPC-c10e466455a37c6ad6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1a0d010f-1c33-432c-b0f5-8cf4e8053099, version 1.0
Description : Unknown RPC service
Annotation : IdSegSrv service
Type : Local RPC service
Named pipe : LRPC-c10e466455a37c6ad6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : audit

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : securityevent

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSARPC_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsacap

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_IDPEXT_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LSA_EAS_ENDPOINT

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsapolicylookup

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : lsasspirpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : protected_storage

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : SidKey Local End Point

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Local RPC service
Named pipe : samss lpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Local RPC service
Named pipe : LRPC-310771301a7cade617

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-310771301a7cade617

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-310771301a7cade617

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-310771301a7cade617

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-310771301a7cade617

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f2c9b409-c1c9-4100-8639-d8ab1486694a, version 1.0
Description : Unknown RPC service
Annotation : Witness Client Upcall Server
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : eb081a0d-10ee-478a-a1dd-50995283e7a8, version 3.0
Description : Unknown RPC service
Annotation : Witness Client Test Interface
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Local RPC service
Named pipe : nlaplg

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : abfb6ca3-0c5e-4734-9285-0aee72fe8d1c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3f12fd1215097e06bc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b37f900a-eae4-4304-a2ab-12bb668c0188, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3f12fd1215097e06bc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b3781086-6a54-489b-91c8-51d067172ab7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3f12fd1215097e06bc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e7f76134-9ef5-4949-a2d6-3368cc0988f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3f12fd1215097e06bc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7aeb6705-3ae6-471a-882d-f39c109edc12, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-3f12fd1215097e06bc

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 666f7270-6c69-7365-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 6c637067-6569-746e-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 24d1f7c7-76af-4f28-9ccd-7f6cb6468601
UUID : 2eb08e3e-639f-4fba-97b1-14f878961076, version 1.0
Description : Unknown RPC service
Annotation : Group Policy RPC Interface
Type : Local RPC service
Named pipe : LRPC-64ef91a5d30d5f12cb

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 736e6573-0000-0000-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30b044a5-a225-43f0-b3a4-e060df91f9c1, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : senssvc

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : senssvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE00FEAFA142CF91CDFDDD257E9430

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : IUserProfile2

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : senssvc

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07f399f3465bca8f02

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : ubpmtaskhostchannel

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9f44df71f0ead87414

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : DeviceSetupManager

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : SessEnvPrivateRpc

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-8253d55dfd4da8c728

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-01a2b1b1a430dbb190

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : df4df73a-c52d-4e3a-8003-8437fdf8302a, version 0.0
Description : Unknown RPC service
Annotation : WM_WindowManagerRPC\Server
Type : Local RPC service
Named pipe : LRPC-6538051a2545b3eb74

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-6538051a2545b3eb74

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : dd490425-5325-4565-b774-7e27d6c09c24, version 1.0
Description : Unknown RPC service
Annotation : Base Firewall Engine API
Type : Local RPC service
Named pipe : LRPC-37b279713dbc0bb761

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6538051a2545b3eb74

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-37b279713dbc0bb761

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b006dd53e7062796a5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6538051a2545b3eb74

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-37b279713dbc0bb761

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f47433c3-3e9d-4157-aad4-83aa1f5c2d4c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b006dd53e7062796a5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-6538051a2545b3eb74

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-37b279713dbc0bb761

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2fb92682-6599-42dc-ae13-bd2ca89bd11c, version 1.0
Description : Unknown RPC service
Annotation : Fw APIs
Type : Local RPC service
Named pipe : LRPC-b006dd53e7062796a5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7ea70bcf-48af-4f6a-8968-6a440754d5fa, version 1.0
Description : Unknown RPC service
Annotation : NSI server endpoint
Type : Local RPC service
Named pipe : LRPC-7cc765566d3a0c9389

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : LRPC-7cc765566d3a0c9389

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3473dd4d-2e88-4006-9cba-22570909dd10, version 5.0
Description : Unknown RPC service
Annotation : WinHttp Auto-Proxy Service
Type : Local RPC service
Named pipe : OLE7D65822AE0947E0243B6F9FCB1F7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a4b8d482-80ce-40d6-934d-b22a01a44fe7, version 1.0
Description : Unknown RPC service
Annotation : LicenseManager
Type : Local RPC service
Named pipe : LicenseServiceEndpoint

Object UUID : b5ccd5ef-4238-440b-bba0-999f828f1cfe
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a500d4c6-0dd1-4543-bc0c-d5f93486eaf8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-9cdf61a13794655db5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : LRPC-9cdf61a13794655db5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-9cdf61a13794655db5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : LRPC-9cdf61a13794655db5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-c4e9af53d5a84ee279

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-9cdf61a13794655db5

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : eventlog

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : dhcpcsvc6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : dhcpcsvc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Local RPC service
Named pipe : LRPC-10653a145293eb97d5

Object UUID : fdd099c6-df06-4904-83b4-a87a27903c70
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5222821f-d5e2-4885-84f1-5f6185a0ec41, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint for NCB Reset module
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : OLE93A08A01A65E903AEB1AB71EDBE9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 880fd55e-43b9-11e0-b1a8-cf4edfd72085, version 1.0
Description : Unknown RPC service
Annotation : KAPI Service endpoint
Type : Local RPC service
Named pipe : LRPC-44dcd1ebe2cbc2cd03

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : OLE93A08A01A65E903AEB1AB71EDBE9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : e40f7b57-7a25-4cd3-a135-7f7d3df9d16b, version 1.0
Description : Unknown RPC service
Annotation : Network Connection Broker server endpoint
Type : Local RPC service
Named pipe : LRPC-44dcd1ebe2cbc2cd03

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : OLE93A08A01A65E903AEB1AB71EDBE9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : LRPC-44dcd1ebe2cbc2cd03

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Local RPC service
Named pipe : trkwks

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE93A08A01A65E903AEB1AB71EDBE9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-44dcd1ebe2cbc2cd03

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : trkwks

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-c9d41ef78cbbff2ea6

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-013c17edc3bc742be7

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE93A08A01A65E903AEB1AB71EDBE9

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : TSUMRPD_PRINT_DRV_LPC_API

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-44dcd1ebe2cbc2cd03

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : trkwks

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 169c453b-5955-4672-be44-21f61e9ef18f, version 1.0
Description : Unknown RPC service
Annotation : INgcContainerEnum
Type : Local RPC service
Named pipe : LRPC-c02f804775f1d89bba

Object UUID : 3bdb59a0-d736-4d44-9074-c1ee00000001
UUID : f3f09ffd-fbcf-4291-944d-70ad6e0e73bb, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-b3f895f5590ed33038

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000001
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : WMsgKRpc0A8061

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 085b0334-e454-4d91-9b8c-4134f9e793f3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8782d3b9-ebbd-4644-a3d8-e8725381919b, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3b338d89-6cfa-44b8-847e-531531bc9992, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : umpo

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : actkernel

Object UUID : 6d726574-7273-0076-0000-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE861407DC54674E95B94452A0321B

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d4e75c3812b0980434

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE861407DC54674E95B94452A0321B

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d4e75c3812b0980434

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07be557843fe31b55b

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE861407DC54674E95B94452A0321B

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d4e75c3812b0980434

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07be557843fe31b55b

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE861407DC54674E95B94452A0321B

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d4e75c3812b0980434

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07be557843fe31b55b

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : csebpub

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : dabrpc

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-52a210e485cf4667b4

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : umpo

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : actkernel

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-aa06fd7753feb30883

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LSMApi

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-4903d510700ac99bae

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : OLE861407DC54674E95B94452A0321B

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-d4e75c3812b0980434

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Local RPC service
Named pipe : LRPC-07be557843fe31b55b

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following DCERPC services are available remotely :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\XHWAKEYESRV

Object UUID : b08669ee-8cb5-43a5-a017-84fe00000000
UUID : 76f226c3-ec14-4325-8a99-6a46348418af, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\InitShutdown
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86, version 2.0
Description : Unknown RPC service
Annotation : KeyIso
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 51a227ae-825b-41f2-b4a9-1ac9557a1018, version 1.0
Description : Unknown RPC service
Annotation : Ngc Pop Key Service
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
Named pipe : \pipe\lsass
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 7f1343fe-50a9-4927-a778-0c5859517bac, version 1.0
Description : Unknown RPC service
Annotation : DfsDs service
Type : Remote RPC service
Named pipe : \PIPE\wkssvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1ff70682-0a51-30e8-076d-740be8cee98b, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 378e52b0-c0a9-11cf-822d-00aa0051e40f, version 1.0
Description : Scheduler Service
Windows process : svchost.exe
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 73736573-6f69-656e-6e76-000000000000
UUID : c9ac6db5-82b7-4e55-ae8a-e464ed7b4277, version 1.0
Description : Unknown RPC service
Annotation : Impl friendly name
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 33d84484-3626-47ee-8c6f-e7e98b113be1, version 2.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \PIPE\atsvc
Netbios name : \\XHWAKEYESRV

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\SessEnvPublicRpc
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Remote RPC service
Named pipe : \pipe\eventlog
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0767a036-0d22-48aa-ba69-b619480f38cb, version 1.0
Description : Unknown RPC service
Annotation : PcaSvc
Type : Remote RPC service
Named pipe : \pipe\trkwks
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : be7f785e-0e3a-4ab7-91de-7e46e443be29, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\trkwks
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 54b4c689-969a-476f-8dc2-990885e9f562, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\trkwks
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2d98a740-581d-41b9-aa0d-a88b9d5ce938, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c605f9fb-f0a3-4e2a-a073-73560f8d9e3e, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2c7fd9ce-e706-4b40-b412-953107ef9bb0, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c521facf-09a9-42c5-b155-72388595cbf0, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 1832bcf6-cab8-41d4-85d2-c9410764f75a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4dace966-a243-4450-ae3f-9b7bcb5315b8, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 55e6b932-1979-45d6-90c5-7f6270724112, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76c217bc-c8b4-4201-a745-373ad9032b1a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 88abcbc3-34ea-76ae-8215-767520655a23, version 0.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2513bcbe-6cd4-4348-855e-7efb3c336dd3, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 20c40295-8dba-48e6-aebf-3e78ef3bb144, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b8cadbaf-e84b-46b9-84f2-6f71c03f9e55, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : db57eb61-1aa2-4906-9396-23e8b8024c32
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 697dcda9-3ba9-4eb2-9247-e11f1901b0d2, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 9e56cbc5-e634-4267-818e-ffa7dce1fa86
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 9b008953-f195-4bf9-bde0-4471971e58ed, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : fc48cd89-98d6-4628-9839-86f7a3e4161a, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
Named pipe : \pipe\LSM_API_service
Netbios name : \\XHWAKEYESRV

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49664/dce-rpc


The following DCERPC services are available on TCP port 49664 :

Object UUID : 765294ba-60bc-48b8-92e9-89fd77769d91
UUID : d95afe70-a6d5-4259-822e-2c84da1ddb0d, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49664
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49665/dce-rpc


The following DCERPC services are available on TCP port 49665 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : f6beaff7-1e19-4fbb-9f8f-b89e2018337c, version 1.0
Description : Unknown RPC service
Annotation : Event log TCPIP
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6, version 1.0
Description : Unknown RPC service
Annotation : DHCPv6 Client LRPC Endpoint
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5, version 1.0
Description : DHCP Client Service
Windows process : svchost.exe
Annotation : DHCP Client LRPC Endpoint
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 30adc50c-5cbc-46ce-9a0e-91914789e23c, version 1.0
Description : Unknown RPC service
Annotation : NRP server endpoint
Type : Remote RPC service
TCP Port : 49665
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49666/dce-rpc


The following DCERPC services are available on TCP port 49666 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 86d35949-83c9-4044-b424-db363231fd0c, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 3a9ef155-691d-4449-8d05-09ad57031823, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 29770a8f-829b-4158-90a2-78cd488501f7, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : b18fbab6-56f8-4702-84e0-41053293a869, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0d3c7f20-1c8d-4654-a1b3-51563b298bda, version 1.0
Description : Unknown RPC service
Annotation : UserMgrCli
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : a398e520-d59a-4bdd-aa7a-3c1e0303a511, version 1.0
Description : Unknown RPC service
Annotation : IKE/Authip API
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 552d076a-cb29-4e44-8b6a-d15e59e2c0af, version 1.0
Description : Unknown RPC service
Annotation : IP Transition Configuration endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 2e6035b2-e8f1-41a7-a044-656b439c4c34, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager provider server endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c36be077-e14b-4fe9-8abc-e856ef4f048b, version 1.0
Description : Unknown RPC service
Annotation : Proxy Manager client server endpoint
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1, version 1.0
Description : Unknown RPC service
Annotation : Adh APIs
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

Object UUID : 582a47b2-bcd8-4d3c-8acb-fe09d5bd6eec
UUID : d09bdeb5-6171-4a34-bfe2-06fa82652568, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49666
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49667/dce-rpc


The following DCERPC services are available on TCP port 49667 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345678-1234-abcd-ef00-0123456789ab, version 1.0
Description : IPsec Services (Windows XP & 2003)
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : ae33069b-a2a8-46ee-a235-ddfd339be281, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 4a452661-8290-4b36-8fbe-7f4093a94978, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.73

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 76f03f96-cdfd-44fc-a22c-64950a001209, version 1.0
Description : Unknown RPC service
Type : Remote RPC service
TCP Port : 49667
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49668/dce-rpc


The following DCERPC services are available on TCP port 49668 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 6b5bdd1e-528c-422c-af8c-a4079be4fe48, version 1.0
Description : Unknown RPC service
Annotation : Remote Fw APIs
Type : Remote RPC service
TCP Port : 49668
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49670/dce-rpc


The following DCERPC services are available on TCP port 49670 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 367abb81-9844-35f1-ad32-98f038001003, version 2.0
Description : Service Control Manager
Windows process : svchost.exe
Type : Remote RPC service
TCP Port : 49670
IP : 172.17.100.73

10736 - DCE Services Enumeration
-
Synopsis
A DCE/RPC service is running on the remote host.
Description
By sending a Lookup request to the portmapper (TCP 135 or epmapper PIPE) it was possible to enumerate the Distributed Computing Environment (DCE) services running on the remote port. Using this information it is possible to connect and bind to each service by sending an RPC request to the remote port/pipe.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/08/26, Modified: 2021/10/04
Plugin Output

tcp/49672/dce-rpc


The following DCERPC services are available on TCP port 49672 :

Object UUID : 00000000-0000-0000-0000-000000000000
UUID : 12345778-1234-abcd-ef00-0123456789ac, version 1.0
Description : Security Account Manager
Windows process : lsass.exe
Type : Remote RPC service
TCP Port : 49672
IP : 172.17.100.73

139785 - DISM Package List (Windows)
-
Synopsis
Use DISM to extract package info from the host.
Description
Using the Deployment Image Servicing Management tool, this plugin enumerates installed packages.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/08/25, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following packages were enumerated using the Deployment Image Servicing and Management Tool:

Package : Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Foundation
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-gb-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:40 PM

Package : Microsoft-Windows-LanguageFeatures-Basic-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:41 PM

Package : Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:46 PM

Package : Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 2/2/2018 6:47 PM

Package : Microsoft-Windows-NetFx3-OnDemand-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : OnDemand Pack
Install Time : 6/12/2024 10:46 AM

Package : Microsoft-Windows-Security-SPP-Component-SKU-ServerDatacenter-GVLK-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 2/2/2018 7:27 PM

Package : Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0
State : Installed
Release Type : Language Pack
Install Time : 2/2/2018 6:13 PM

Package : Microsoft-Windows-ServerCore-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-ServerCore-Server-Common-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Microsoft-Windows-ServerCore-SKU-Foundation-Package~31bf3856ad364e35~amd64~~10.0.14393.0
State : Installed
Release Type : Feature Pack
Install Time : 7/16/2016 1:25 PM

Package : Package_for_KB4049065~31bf3856ad364e35~amd64~~10.0.1.3
State : Installed
Release Type : Update
Install Time : 2/2/2018 7:21 PM

Package : Package_for_KB4054590~31bf3856ad364e35~amd64~~10.0.1.2072
State : Installed
Release Type : Update
Install Time : 6/6/2024 8:01 AM

Package : Package_for_KB5037016~31bf3856ad364e35~amd64~~14393.6896.1.5
State : Installed
Release Type : Security Update
Install Time : 5/31/2024 11:38 AM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~14393.1884.1.3
State : Superseded
Release Type : Security Update
Install Time : 2/2/2018 7:21 PM

Package : Package_for_RollupFix~31bf3856ad364e35~amd64~~14393.2273.1.4
State : Partially Installed
Release Type : Update
Install Time : 5/31/2024 11:38 AM

84239 - Debugging Log Report
-
Synopsis
This plugin gathers the logs written by other plugins and reports them.
Description
Logs generated by other plugins are reported by this plugin. Plugin debugging must be enabled in the policy in order for this plugin to run.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/06/17, Modified: 2025/07/14
Plugin Output

tcp/0

Plugin debug log(s) have been attached.
55472 - Device Hostname
-
Synopsis
It was possible to determine the remote system hostname.
Description
This plugin reports a device's hostname collected via SSH or WMI.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/06/30, Modified: 2025/12/15
Plugin Output

tcp/0


Hostname : XHWAKEYESRV
XHWAKEYESRV (WMI)
54615 - Device Type
-
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output

tcp/0

Remote device type : general-purpose
Confidence level : 100

19689 - Embedded Web Server Detection
-
Synopsis
The remote web server is embedded.
Description
The remote web server cannot host user-supplied CGIs. CGI scanning will be disabled on this server.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/09/14, Modified: 2025/09/29
Plugin Output

tcp/5800/www

71246 - Enumerate Local Group Memberships
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.
Description
Nessus was able to connect to a host via SMB to retrieve a list of local Groups and their Members.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering Group data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/12/06, Modified: 2025/12/15
Plugin Output

tcp/0

Group Name : Access Control Assistance Operators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-579
Members :

Group Name : Administrators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-544
Members :
Name : Production
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-500
Name : LKPAdmin
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-1005
Name : tidua
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-1006

Group Name : Backup Operators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-551
Members :

Group Name : Certificate Service DCOM Access
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-574
Members :

Group Name : Cryptographic Operators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-569
Members :

Group Name : Distributed COM Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-562
Members :

Group Name : Event Log Readers
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-573
Members :

Group Name : Guests
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-546
Members :
Name : Guest
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-501

Group Name : Hyper-V Administrators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-578
Members :

Group Name : IIS_IUSRS
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-568
Members :

Group Name : Network Configuration Operators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-556
Members :

Group Name : Performance Log Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-559
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Performance Monitor Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-558
Members :
Name : MSSQLSERVER
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLSERVERAGENT
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : MSSQL$SQLEXPRESS
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
Name : SQLAgent$SQLEXPRESS
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : Power Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-547
Members :

Group Name : Print Operators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-550
Members :

Group Name : RDS Endpoint Servers
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-576
Members :

Group Name : RDS Management Servers
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-577
Members :

Group Name : RDS Remote Access Servers
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-575
Members :

Group Name : Remote Desktop Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-555
Members :

Group Name : Remote Management Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-580
Members :

Group Name : Replicator
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-552
Members :

Group Name : Storage Replica Administrators
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-582
Members :

Group Name : System Managed Accounts Group
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-581
Members :
Name : DefaultAccount
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-503

Group Name : Users
Host Name : XHWAKEYESRV
Group SID : S-1-5-32-545
Members :
Name : INTERACTIVE
Domain : XHWAKEYESRV
Class : Win32_SystemAccount
SID : S-1-5-4
Name : Authenticated Users
Domain : XHWAKEYESRV
Class : Win32_SystemAccount
SID : S-1-5-11
Name : LKPAdmin
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-1005
Name : tidua
Domain : XHWAKEYESRV
Class : Win32_UserAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-1006

Group Name : KLAdmins
Host Name : XHWAKEYESRV
Group SID : S-1-5-21-3119273522-2427777209-1705870880-1003
Members :
Name : ksnproxy
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : KLOperators
Host Name : XHWAKEYESRV
Group SID : S-1-5-21-3119273522-2427777209-1705870880-1004
Members :

Group Name : SQLRUserGroup
Host Name : XHWAKEYESRV
Group SID : S-1-5-21-3119273522-2427777209-1705870880-1002
Members :
Name : MSSQLLaunchpad
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServer2005SQLBrowserUser$WIN-N80Q16OTCPS
Host Name : XHWAKEYESRV
Group SID : S-1-5-21-3119273522-2427777209-1705870880-1000
Members :
Name : SQLBrowser
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :

Group Name : SQLServerMSASUser$WIN-N80Q16OTCPS$MSSQLSERVER
Host Name : XHWAKEYESRV
Group SID : S-1-5-21-3119273522-2427777209-1705870880-1001
Members :
Name : MSSQLServerOLAPService
Domain : NT SERVICE
Class : Win32_SystemAccount
SID :
72684 - Enumerate Users via WMI
-
Synopsis
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI.
Description
Nessus was able to connect to a host via SMB to retrieve a list of users using WMI. Only identities that the authenticated SMB user has permissions to view will be retrieved by this plugin.

Note: Unable to query local Domain Controllers during Agent scans.
Rendering User data obtained by plugin 171956.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/02/25, Modified: 2025/12/15
Plugin Output

tcp/0


Name : DefaultAccount
SID : S-1-5-21-3119273522-2427777209-1705870880-503
Disabled : True
Lockout : False
Change password : True
Source : Local

Name : Guest
SID : S-1-5-21-3119273522-2427777209-1705870880-501
Disabled : True
Lockout : False
Change password : False
Source : Local

Name : LKPAdmin
SID : S-1-5-21-3119273522-2427777209-1705870880-1005
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : Production
SID : S-1-5-21-3119273522-2427777209-1705870880-500
Disabled : False
Lockout : False
Change password : True
Source : Local

Name : tidua
SID : S-1-5-21-3119273522-2427777209-1705870880-1006
Disabled : False
Lockout : False
Change password : True
Source : Local

No. Of Users : 5
168980 - Enumerate the PATH Variables
-
Synopsis
Enumerates the PATH variable of the current scan user.
Description
Enumerates the PATH variables of the current scan user.
Solution
Ensure that directories listed here are in line with corporate policy.
Risk Factor
None
Plugin Information
Published: 2022/12/21, Modified: 2025/12/18
Plugin Output

tcp/0

Nessus has enumerated the path of the current scan user :

C:\Program Files\Common Files\Oracle\Java\javapath
C:\Program Files (x86)\Common Files\Oracle\Java\javapath
C:\Program Files\Microsoft MPI\Bin\
C:\Windows\system32
C:\Windows
C:\Windows\System32\Wbem
C:\Windows\System32\WindowsPowerShell\v1.0\
C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files\Microsoft SQL Server\150\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\150\DTS\Binn\
C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\
C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\
C:\Program Files (x86)\Microsoft SQL Server\130\Tools\Binn\
C:\Program Files\Microsoft SQL Server\130\Tools\Binn\
C:\Program Files\Microsoft SQL Server\130\DTS\Binn\
C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\
C:\Program Files\Java\jdk-1.8\bin
35716 - Ethernet Card Manufacturer Detection
-
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output

tcp/0


The following card manufacturers were identified :

40:A8:F0:20:84:35 : Hewlett Packard
40:A8:F0:20:84:34 : Hewlett Packard
40:A8:F0:20:84:36 : Hewlett Packard
40:A8:F0:20:84:37 : Hewlett Packard
86420 - Ethernet MAC Addresses
-
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/06/10
Plugin Output

tcp/0

The following is a consolidated list of detected MAC addresses:
- 40:A8:F0:20:84:35
- 40:A8:F0:20:84:34
- 40:A8:F0:20:84:36
- 40:A8:F0:20:84:37
92439 - Explorer Search History
-
Synopsis
Nessus was able to gather a list of items searched for in the Windows UI.
Description
Nessus was able to gather evidence of cached search results from Windows Explorer searches.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0


Explorer search history report attached.
56310 - Firewall Rule Enumeration
-
Synopsis
A firewall is configured on the remote host.
Description
Using the supplied credentials, Nessus was able to get a list of firewall rules from the remote host.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/09/28, Modified: 2020/09/11
Plugin Output

tcp/0

report output too big - ending list here

34196 - Google Chrome Detection (Windows)
-
Synopsis
The remote Windows host contains a web browser.
Description
Google Chrome, a web browser from Google, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0511
Plugin Information
Published: 2008/09/12, Modified: 2025/07/10
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Google\Chrome\Application
Version : 143.0.7499.170

Note that Nessus only looked in the registry for evidence of Google
Chrome. If there are multiple users on this host, you may wish to
enable the 'Perform thorough tests' setting and re-scan. This will
cause Nessus to scan each local user's directory for installs.

84502 - HSTS Missing From HTTPS Server
-
Synopsis
The remote web server is not enforcing HSTS.
Description
The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.
See Also
Solution
Configure the remote web server to use HSTS.
Risk Factor
None
Plugin Information
Published: 2015/07/02, Modified: 2024/08/09
Plugin Output

tcp/51528/www


HTTP/1.1 200

Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Date: Fri, 09 Jan 2026 23:36:51 GMT
Keep-Alive: timeout=60
Connection: keep-alive


The remote HTTPS server does not send the HTTP
"Strict-Transport-Security" header.

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/80/www

Based on the response to an OPTIONS request :

- HTTP methods GET HEAD POST TRACE OPTIONS are allowed on :

/

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/51528/www

Based on the response to an OPTIONS request :

- HTTP methods HEAD OPTIONS POST GET are allowed on :

/

43111 - HTTP Methods Allowed (per directory)
-
Synopsis
This plugin determines which HTTP methods are allowed on various CGI directories.
Description
By calling the OPTIONS method, it is possible to determine which HTTP methods are allowed on each directory.

The following HTTP methods are considered insecure:
PUT, DELETE, CONNECT, TRACE, HEAD

Many frameworks and languages treat 'HEAD' as a 'GET' request, albeit one without any body in the response. If a security constraint was set on 'GET' requests such that only 'authenticatedUsers' could access GET requests for a particular servlet or resource, it would be bypassed for the 'HEAD' version. This allowed unauthorized blind submission of any privileged GET request.

As this list may be incomplete, the plugin also tests - if 'Thorough tests' are enabled or 'Enable web applications tests' is set to 'yes'
in the scan policy - various known HTTP methods on each directory and considers them as unsupported if it receives a response code of 400, 403, 405, or 501.

Note that the plugin output is only informational and does not necessarily indicate the presence of any security vulnerabilities.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/12/10, Modified: 2022/04/11
Plugin Output

tcp/51529/www

Based on the response to an OPTIONS request :

- HTTP methods HEAD OPTIONS POST GET are allowed on :

/

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/80/www

The remote web server type is :

Microsoft-IIS/10.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5800/www

The remote web server type is :

RealVNC/E4

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/5985/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

10107 - HTTP Server Type and Version
-
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output

tcp/47001/www

The remote web server type is :

Microsoft-HTTPAPI/2.0

12053 - Host Fully Qualified Domain Name (FQDN) Resolution
-
Synopsis
It was possible to resolve the name of the remote host.
Description
Nessus was able to resolve the fully qualified domain name (FQDN) of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2004/02/11, Modified: 2025/03/13
Plugin Output

tcp/0


172.17.100.73 resolves as XHwakEyeSrv.

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/80/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : OPTIONS, TRACE, GET, HEAD, POST
Headers :

Server: Microsoft-IIS/10.0
Date: Fri, 09 Jan 2026 23:38:31 GMT
Content-Length: 0

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/5985/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 09 Jan 2026 23:38:31 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/47001/www


Response Code : HTTP/1.1 404 Not Found

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : no
Options allowed : (Not implemented)
Headers :

Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 09 Jan 2026 23:38:31 GMT
Connection: close
Content-Length: 315

Response Body :

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/51528/www


Response Code : HTTP/1.1 200

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : yes
Keep-Alive : yes
Options allowed : GET, HEAD, POST, PUT, DELETE, OPTIONS
Headers :

Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Date: Fri, 09 Jan 2026 23:38:32 GMT
Keep-Alive: timeout=60
Connection: keep-alive

Response Body :




<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<title>Apache Tomcat/9.0.104</title>
<link href="favicon.ico" rel="icon" type="image/x-icon" />
<link href="tomcat.css" rel="stylesheet" type="text/css" />
</head>

<body>
<div id="wrapper">
<div id="navigation" class="curved container">
<span id="nav-home"><a href="https://tomcat.apache.org/">Home</a></span>
<span id="nav-hosts"><a href="/docs/">Documentation</a></span>
<span id="nav-config"><a href="/docs/config/">Configuration</a></span>
<span id="nav-examples"><a href="/examples/">Examples</a></span>
<span id="nav-wiki"><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Wiki</a></span>
<span id="nav-lists"><a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></span>
<span id="nav-help"><a href="https://tomcat.apache.org/findhelp.html">Find Help</a></span>
<br class="separator" />
</div>
<div id="asf-box">
<h1>Apache Tomcat/9.0.104</h1>
</div>
<div id="upper" class="curved container">
<div id="congrats" class="curved container">
<h2>If you're seeing this, you've successfully installed Tomcat. Congratulations!</h2>
</div>
<div id="notice">
<img id="tomcat-logo" src="tomcat.svg" alt="[tomcat logo]" />
<div id="tasks">
<h3>Recommended Reading:</h3>
<h4><a href="/docs/security-howto.html">Security Considerations How-To</a></h4>
<h4><a href="/docs/manager-howto.html">Manager Application How-To</a></h4>
<h4><a href="/docs/cluster-howto.html">Clustering/Session Replication How-To</a></h4>
</div>
</div>
<div id="actions">
<div class="button">
<a class="container shadow" href="/manager/status"><span>Server Status</span></a>
</div>
<div class="button">
<a class="container shadow" href="/manager/html"><span>Manager App</span></a>
</div>
<div class="button">
<a class="container shadow" href="/host-manager/html"><span>Host Manager</span></a>
</div>
</div>
<br class="separator" />
</div>
<div id="middle" class="curved container">
<h3>Developer Quick Start</h3>
<div class="col25">
<div class="container">
<p><a href="/docs/setup.html">Tomcat Setup</a></p>
<p><a href="/docs/appdev/">First Web Application</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="/docs/realm-howto.html">Realms &amp; AAA</a></p>
<p><a href="/docs/jndi-datasource-examples-howto.html">JDBC DataSources</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="/examples/">Examples</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="https://cwiki.apache.org/confluence/display/TOMCAT/Specifications">Servlet Specifications</a></p>
<p><a href="https://cwiki.apache.org/confluence/display/TOMCAT/Tomcat+Versions">Tomcat Versions</a></p>
</div>
</div>
<br class="separator" />
</div>
<div id="lower">
<div id="low-manage" class="">
<div class="curved container">
<h3>Managing Tomcat</h3>
<p>For security, access to the <a href="/manager/html">manager webapp</a> is restricted.
Users are defined in:</p>
<pre>$CATALINA_HOME/conf/tomcat-users.xml</pre>
<p>In Tomcat 9.0 access to the manager application is split between
different users. &nbsp; <a href="/docs/manager-howto.html">Read more...</a></p>
<br />
<h4><a href="/docs/RELEASE-NOTES.txt">Release Notes</a></h4>
<h4><a href="/docs/changelog.html">Changelog</a></h4>
<h4><a href="https://tomcat.apache.org/migration.html">Migration Guide</a></h4>
<h4><a href="https://tomcat.apache.org/security.html">Security Notices</a></h4>
</div>
</div>
<div id="low-docs" class="">
<div class="curved container">
<h3>Documentation</h3>
<h4><a href="/docs/">Tomcat 9.0 Documentation</a></h4>
<h4><a href="/docs/config/">Tomcat 9.0 Configuration</a></h4>
<h4><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Tomcat Wiki</a></h4>
<p>Find additional important configuration information in:</p>
<pre>$CATALINA_HOME/RUNNING.txt</pre>
<p>Developers may be interested in:</p>
<ul>
<li><a href="https://tomcat.apache.org/bugreport.html">Tomcat 9.0 Bug Database</a></li>
<li><a href="/docs/api/index.html">Tomcat 9.0 JavaDocs</a></li>
<li><a href="https://github.com/apache/tomcat/tree/9.0.x">Tomcat 9.0 Git Repository at GitHub</a></li>
</ul>
</div>
</div>
<div id="low-help" class="">
<div class="curved container">
<h3>Getting Help</h3>
<h4><a href="https://tomcat.apache.org/faq/">FAQ</a> and <a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></h4>
<p>The following mailing lists are available:</p>
<ul>
<li id="list-announce"><strong><a href="https://tomcat.apache.org/lists.html#tomcat-announce">tomcat-announce</a><br />
Important announcements, releases, security vulnerability notifications. (Low volume).</strong>
</li>
<li><a href="https://tomcat.apache.org/lists.html#tomcat-users">tomcat-users</a><br />
User support and discussion
</li>
<li><a href="https://tomcat.apache.org/lists.html#taglibs-user">taglibs-user</a><br />
User support and discussion for <a href="https://tomcat.apache.org/taglibs/">Apache Taglibs</a>
</li>
<li><a href="https://tomcat.apache.org/lists.html#tomcat-dev">tomcat-dev</a><br />
Development mailing list, including commit messages
</li>
</ul>
</div>
</div>
<br class="separator" />
</div>
<div id="footer" class="curved container">
<div class="col20">
<div class="container">
<h4>Other Downloads</h4>
<ul>
<li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li>
<li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li>
<li><a href="https://tomcat.apache.org/taglibs/">Taglibs</a></li>
<li><a href="/docs/deployer-howto.html">Deployer</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Other Documentation</h4>
<ul>
<li><a href="https://tomcat.apache.org/connectors-doc/">Tomcat Connectors</a></li>
<li><a href="https://tomcat.apache.org/connectors-doc/">mod_jk Documentation</a></li>
<li><a href="https://tomcat.apache.org/native-doc/">Tomcat Native</a></li>
<li><a href="/docs/deployer-howto.html">Deployer</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Get Involved</h4>
<ul>
<li><a href="https://tomcat.apache.org/getinvolved.html">Overview</a></li>
<li><a href="https://tomcat.apache.org/source.html">Source Repositories</a></li>
<li><a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></li>
<li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Wiki</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Miscellaneous</h4>
<ul>
<li><a href="https://tomcat.apache.org/contact.html">Contact</a></li>
<li><a href="https://tomcat.apache.org/legal.html">Legal</a></li>
<li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li>
<li><a href="https://www.apache.org/foundation/thanks.html">Thanks</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Apache Software Foundation</h4>
<ul>
<li><a href="https://tomcat.apache.org/whoweare.html">Who We Are</a></li>
<li><a href="https://tomcat.apache.org/heritage.html">Heritage</a></li>
<li><a href="https://www.apache.org">Apache Home</a></li>
<li><a href="https://tomcat.apache.org/resources.html">Resources</a></li>
</ul>
</div>
</div>
<br class="separator" />
</div>
<p class="copyright">Copyright &copy;1999-2026 Apache Software Foundation. All Rights Reserved</p>
</div>
</body>

</html>

24260 - HyperText Transfer Protocol (HTTP) Information
-
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...

This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output

tcp/51529/www


Response Code : HTTP/1.1 200

Protocol version : HTTP/1.1
HTTP/2 TLS Support: No
HTTP/2 Cleartext Support: No
SSL : no
Keep-Alive : yes
Options allowed : GET, HEAD, POST, PUT, DELETE, OPTIONS
Headers :

Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Date: Fri, 09 Jan 2026 23:38:32 GMT
Keep-Alive: timeout=20
Connection: keep-alive

Response Body :




<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<title>Apache Tomcat/9.0.104</title>
<link href="favicon.ico" rel="icon" type="image/x-icon" />
<link href="tomcat.css" rel="stylesheet" type="text/css" />
</head>

<body>
<div id="wrapper">
<div id="navigation" class="curved container">
<span id="nav-home"><a href="https://tomcat.apache.org/">Home</a></span>
<span id="nav-hosts"><a href="/docs/">Documentation</a></span>
<span id="nav-config"><a href="/docs/config/">Configuration</a></span>
<span id="nav-examples"><a href="/examples/">Examples</a></span>
<span id="nav-wiki"><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Wiki</a></span>
<span id="nav-lists"><a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></span>
<span id="nav-help"><a href="https://tomcat.apache.org/findhelp.html">Find Help</a></span>
<br class="separator" />
</div>
<div id="asf-box">
<h1>Apache Tomcat/9.0.104</h1>
</div>
<div id="upper" class="curved container">
<div id="congrats" class="curved container">
<h2>If you're seeing this, you've successfully installed Tomcat. Congratulations!</h2>
</div>
<div id="notice">
<img id="tomcat-logo" src="tomcat.svg" alt="[tomcat logo]" />
<div id="tasks">
<h3>Recommended Reading:</h3>
<h4><a href="/docs/security-howto.html">Security Considerations How-To</a></h4>
<h4><a href="/docs/manager-howto.html">Manager Application How-To</a></h4>
<h4><a href="/docs/cluster-howto.html">Clustering/Session Replication How-To</a></h4>
</div>
</div>
<div id="actions">
<div class="button">
<a class="container shadow" href="/manager/status"><span>Server Status</span></a>
</div>
<div class="button">
<a class="container shadow" href="/manager/html"><span>Manager App</span></a>
</div>
<div class="button">
<a class="container shadow" href="/host-manager/html"><span>Host Manager</span></a>
</div>
</div>
<br class="separator" />
</div>
<div id="middle" class="curved container">
<h3>Developer Quick Start</h3>
<div class="col25">
<div class="container">
<p><a href="/docs/setup.html">Tomcat Setup</a></p>
<p><a href="/docs/appdev/">First Web Application</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="/docs/realm-howto.html">Realms &amp; AAA</a></p>
<p><a href="/docs/jndi-datasource-examples-howto.html">JDBC DataSources</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="/examples/">Examples</a></p>
</div>
</div>
<div class="col25">
<div class="container">
<p><a href="https://cwiki.apache.org/confluence/display/TOMCAT/Specifications">Servlet Specifications</a></p>
<p><a href="https://cwiki.apache.org/confluence/display/TOMCAT/Tomcat+Versions">Tomcat Versions</a></p>
</div>
</div>
<br class="separator" />
</div>
<div id="lower">
<div id="low-manage" class="">
<div class="curved container">
<h3>Managing Tomcat</h3>
<p>For security, access to the <a href="/manager/html">manager webapp</a> is restricted.
Users are defined in:</p>
<pre>$CATALINA_HOME/conf/tomcat-users.xml</pre>
<p>In Tomcat 9.0 access to the manager application is split between
different users. &nbsp; <a href="/docs/manager-howto.html">Read more...</a></p>
<br />
<h4><a href="/docs/RELEASE-NOTES.txt">Release Notes</a></h4>
<h4><a href="/docs/changelog.html">Changelog</a></h4>
<h4><a href="https://tomcat.apache.org/migration.html">Migration Guide</a></h4>
<h4><a href="https://tomcat.apache.org/security.html">Security Notices</a></h4>
</div>
</div>
<div id="low-docs" class="">
<div class="curved container">
<h3>Documentation</h3>
<h4><a href="/docs/">Tomcat 9.0 Documentation</a></h4>
<h4><a href="/docs/config/">Tomcat 9.0 Configuration</a></h4>
<h4><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Tomcat Wiki</a></h4>
<p>Find additional important configuration information in:</p>
<pre>$CATALINA_HOME/RUNNING.txt</pre>
<p>Developers may be interested in:</p>
<ul>
<li><a href="https://tomcat.apache.org/bugreport.html">Tomcat 9.0 Bug Database</a></li>
<li><a href="/docs/api/index.html">Tomcat 9.0 JavaDocs</a></li>
<li><a href="https://github.com/apache/tomcat/tree/9.0.x">Tomcat 9.0 Git Repository at GitHub</a></li>
</ul>
</div>
</div>
<div id="low-help" class="">
<div class="curved container">
<h3>Getting Help</h3>
<h4><a href="https://tomcat.apache.org/faq/">FAQ</a> and <a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></h4>
<p>The following mailing lists are available:</p>
<ul>
<li id="list-announce"><strong><a href="https://tomcat.apache.org/lists.html#tomcat-announce">tomcat-announce</a><br />
Important announcements, releases, security vulnerability notifications. (Low volume).</strong>
</li>
<li><a href="https://tomcat.apache.org/lists.html#tomcat-users">tomcat-users</a><br />
User support and discussion
</li>
<li><a href="https://tomcat.apache.org/lists.html#taglibs-user">taglibs-user</a><br />
User support and discussion for <a href="https://tomcat.apache.org/taglibs/">Apache Taglibs</a>
</li>
<li><a href="https://tomcat.apache.org/lists.html#tomcat-dev">tomcat-dev</a><br />
Development mailing list, including commit messages
</li>
</ul>
</div>
</div>
<br class="separator" />
</div>
<div id="footer" class="curved container">
<div class="col20">
<div class="container">
<h4>Other Downloads</h4>
<ul>
<li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li>
<li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li>
<li><a href="https://tomcat.apache.org/taglibs/">Taglibs</a></li>
<li><a href="/docs/deployer-howto.html">Deployer</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Other Documentation</h4>
<ul>
<li><a href="https://tomcat.apache.org/connectors-doc/">Tomcat Connectors</a></li>
<li><a href="https://tomcat.apache.org/connectors-doc/">mod_jk Documentation</a></li>
<li><a href="https://tomcat.apache.org/native-doc/">Tomcat Native</a></li>
<li><a href="/docs/deployer-howto.html">Deployer</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Get Involved</h4>
<ul>
<li><a href="https://tomcat.apache.org/getinvolved.html">Overview</a></li>
<li><a href="https://tomcat.apache.org/source.html">Source Repositories</a></li>
<li><a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></li>
<li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/">Wiki</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Miscellaneous</h4>
<ul>
<li><a href="https://tomcat.apache.org/contact.html">Contact</a></li>
<li><a href="https://tomcat.apache.org/legal.html">Legal</a></li>
<li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li>
<li><a href="https://www.apache.org/foundation/thanks.html">Thanks</a></li>
</ul>
</div>
</div>
<div class="col20">
<div class="container">
<h4>Apache Software Foundation</h4>
<ul>
<li><a href="https://tomcat.apache.org/whoweare.html">Who We Are</a></li>
<li><a href="https://tomcat.apache.org/heritage.html">Heritage</a></li>
<li><a href="https://www.apache.org">Apache Home</a></li>
<li><a href="https://tomcat.apache.org/resources.html">Resources</a></li>
</ul>
</div>
</div>
<br class="separator" />
</div>
<p class="copyright">Copyright &copy;1999-2026 Apache Software Foundation. All Rights Reserved</p>
</div>
</body>

</html>

171410 - IP Assignment Method Detection
-
Synopsis
Enumerates the IP address assignment method(static/dynamic).
Description
Enumerates the IP address assignment method(static/dynamic).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/14, Modified: 2025/12/15
Plugin Output

tcp/0

+ isatap.{B3165A43-5C1F-4C46-BA5C-146F1E96E9FD}
+ IPv6
- Address : fe80::5efe:10.20.30.61%7
Assign Method : dynamic
+ MCX
+ IPv4
- Address : 10.195.58.173
Assign Method : static
+ Loopback Pseudo-Interface 1
+ IPv4
- Address : 127.0.0.1
Assign Method : static
+ IPv6
- Address : ::1
Assign Method : static
+ isatap.{F4148D0F-6B11-4627-BAFB-07A83D7854B1}
+ IPv6
- Address : fe80::5efe:10.113.99.73%6
Assign Method : dynamic
+ LAN_73
+ IPv4
- Address : 172.17.100.73
Assign Method : static
+ isatap.{E6E84BA7-497F-4D4E-A902-8ECE5306B573}
+ IPv6
- Address : fe80::5efe:10.195.58.173%3
Assign Method : dynamic
+ NSE
+ IPv4
- Address : 10.20.30.61
Assign Method : static
+ isatap.{A83EDB03-F7DD-4FF9-B5CC-3A1809468FE3}
+ IPv6
- Address : fe80::5efe:172.17.100.73%4
Assign Method : dynamic
+ BSE
+ IPv4
- Address : 10.113.99.73
Assign Method : static

179947 - Intel CPUID detection
-
Synopsis
The processor CPUID was detected on the remote host.
Description
The CPUID of the Intel processor was detected on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/08/18, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Nessus was able to extract the following cpuid: 306E4

92421 - Internet Explorer Typed URLs
-
Synopsis
Nessus was able to enumerate URLs that were manually typed into the Internet Explorer address bar.
Description
Nessus was able to generate a list URLs that were manually typed into the Internet Explorer address bar.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2024/05/08
Plugin Output

tcp/0

http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://xtremsoftindia.com/sw
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141
http://go.microsoft.com/fwlink/p/?LinkId=255141

Internet Explorer typed URL report attached.

148499 - Java Detection and Identification (Windows)
-
Synopsis
Java is installed on the remote Windows host.
Description
One or more instances of Java are installed on the remote Windows host. This may include private JREs bundled with the Java Development Kit (JDK).

- This plugin attempts to detect Oracle and non-Oracle JRE instances such as Zulu Java, Amazon Corretto, AdoptOpenJDK, IBM Java, etc

- Additional instances of Java may be discovered if 'Perform thorough tests' is enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2021/04/14, Modified: 2025/12/16
Plugin Output

tcp/445/cifs


Path : C:\Program Files\Java\jre-1.8\
Version : 8.0.401.10
Application : Oracle Java
Binary Location : C:\Program Files\Java\jre-1.8\bin\java.exe
Details : This Java install appears to be Oracle Java, confirmed by associated
files (high confidence).
Detection Method : Found in Registry

65743 - Java JRE Enabled (Internet Explorer)
-
Synopsis
The remote host has Java JRE enabled for Internet Explorer.
Description
Java JRE is enabled in Internet Explorer. Internet Explorer is no longer supported by Microsoft.
See Also
Solution
Apply Microsoft 'Fix it' 50994 unless Java is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs


Java is enabled for the following ActiveX controls and SIDs :
ActiveX CLSIDs :
{8AD9C840-044E-11D1-B3E9-00805F499D93}
{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}


Note that this check may be incomplete as Nessus can only check the
SIDs of logged on users.
65739 - Java JRE Universally Enabled
-
Synopsis
Java JRE has not been universally disabled on the remote host.
Description
Java JRE has not been universally disabled on the remote host via the Java control panel.
Note that while Java can be individually disabled for each browser, universally disabling Java prevents it from running for all users and browsers.
Functionality to disable Java universally in Windows may not be available in all versions of Java.
See Also
Solution
Disable Java universally unless it is needed.
Risk Factor
None
Plugin Information
Published: 2013/03/29, Modified: 2024/10/02
Plugin Output

tcp/445/cifs

53513 - Link-Local Multicast Name Resolution (LLMNR) Detection
-
Synopsis
The remote device supports LLMNR.
Description
The remote device answered to a Link-local Multicast Name Resolution (LLMNR) request. This protocol provides a name lookup service similar to NetBIOS or DNS. It is enabled by default on modern Windows versions.
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2011/04/21, Modified: 2023/10/17
Plugin Output

udp/5355/llmnr


According to LLMNR, the name of the remote host is 'XHwakEyeSrv'.

160301 - Link-Local Multicast Name Resolution (LLMNR) Service Detection
-
Synopsis
Verify status of the LLMNR service on the remote host.
Description
The Link-Local Multicast Name Resolution (LLMNR) service allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link
See Also
Solution
Make sure that use of this software conforms to your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2022/04/28, Modified: 2022/12/29
Plugin Output

tcp/445/cifs


LLMNR Key SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast not found.

108761 - MSSQL Host Information in NTLM SSP
-
Synopsis
Nessus can obtain information about the host by examining the NTLM SSP message.
Description
Nessus can obtain information about the host by examining the NTLM SSP challenge issued during NTLM authentication, over MSSQL.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/03/30, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Nessus was able to obtain the following information about the host, by
parsing the MSSQL server's NTLM SSP message:

Target Name: XHWAKEYESRV
NetBIOS Domain Name: XHWAKEYESRV
NetBIOS Computer Name: XHWAKEYESRV
DNS Domain Name: XHwakEyeSrv
DNS Computer Name: XHwakEyeSrv
DNS Tree Name: unknown
Product Version: 10.0.14393

92424 - MUICache Program Execution History
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to query the MUIcache registry key to find evidence of program execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

@%systemroot%\system32\windowspowershell\v1.0\powershell.exe,-124 : Document Encryption
@%systemroot%\system32\wuaueng.dll,-400 : Windows Update
@%systemroot%\system32\dnsapi.dll,-103 : Domain Name System (DNS) Server Trust
languagelist : en-US

51351 - Microsoft .NET Framework Detection
-
Synopsis
A software framework is installed on the remote host.
Description
Microsoft .NET Framework, a software framework for Microsoft Windows operating systems, is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0655
Plugin Information
Published: 2010/12/20, Modified: 2025/10/15
Plugin Output

tcp/445/cifs


Nessus detected 5 installs of Microsoft .NET Framework:

Path : C:\Windows\Microsoft.NET\Framework64\v2.0.50727
Version : 2.0.50727
Full Version : 2.0.50727.4927
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.0
Version : 3.0
Full Version : 3.0.30729.4926
SP : 2

Path : C:\Windows\Microsoft.NET\Framework64\v3.5\
Version : 3.5
Full Version : 3.5.30729.4926
SP : 1

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03062
Install Type : Full
Release : 461814

Path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
Version : 4.7.2
Full Version : 4.7.03062
Install Type : Client
Release : 461814
72879 - Microsoft Internet Explorer Enhanced Security Configuration Detection
-
Synopsis
The remote host supports IE Enhanced Security Configuration.
Description
Nessus detects if the remote Windows host supports IE Enhanced Security Configuration (ESC) and if IE ESC features are enabled or disabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2014/03/07, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Type : Admin Groups
Is Enabled : True

Type : User Groups
Is Enabled : True

162560 - Microsoft Internet Explorer Installed
-
Synopsis
A web browser is installed on the remote Windows host.
Description
Microsoft Internet Explorer, a web browser bundled with Microsoft Windows, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/06/28, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\mshtml.dll
Version : 11.0.14393.2273

72367 - Microsoft Internet Explorer Version Detection
-
Synopsis
Internet Explorer is installed on the remote host.
Description
The remote Windows host contains Internet Explorer, a web browser created by Microsoft.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0509
Plugin Information
Published: 2014/02/06, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Version : 11.2273.14393.0

139615 - Microsoft Internet Information Services (IIS) Installed
-
Synopsis
Checks Windows registry keys and executables for a Microsoft Internet Information Services (IIS) installation.
Description
Microsoft Internet Information Services installation (IIS) has been detected on the remote Windows host.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0944
Plugin Information
Published: 2020/08/17, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Windows\system32\inetsrv
Version : 10.0.14393.0

140655 - Microsoft Internet Information Services (IIS) Sites Enumeration
-
Synopsis
Checks IIS configuration file for configured sites and their bound addresses.
Description
Microsoft Internet Information Services configuration file has been parsed to extract information about the existing sites, their protocols, domains and IP addresses.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/09/18, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Nessus found the following sites configured on the remote host:
+ site name: Default Web Site
+ binding 0
- IP address : *
- port : 80
- domain :
- protocol : http
+ binding 1
- IP address : 808
- port : *
- domain :
- protocol : net.tcp
+ binding 2
- IP address : localhost
- port :
- domain :
- protocol : net.msmq
+ binding 3
- IP address : localhost
- port :
- domain :
- protocol : msmq.formatname
+ binding 4
- IP address : *
- port :
- domain :
- protocol : net.pipe
66424 - Microsoft Malicious Software Removal Tool Installed
-
Synopsis
An antimalware application is installed on the remote Windows host.
Description
The Microsoft Malicious Software Removal Tool is installed on the remote host. This tool is an application that attempts to detect and remove known malware from Windows systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/05/15, Modified: 2023/01/10
Plugin Output

tcp/445/cifs


File : C:\Windows\system32\MRT.exe
Version : 5.124.24050.1001
Release at last run : unknown
Report infection information to Microsoft : Yes
174413 - Microsoft ODBC Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft ODBC Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft ODBC Driver for SQL Server:

Path : C:\Windows\System32\msodbcsql17.dll
Version : 17.10.6.1

Path : C:\Windows\System32\msodbcsql13.dll
Version : 13.2.5026.0
174405 - Microsoft OLE DB Driver for SQL Server Installed (Windows)
-
Synopsis
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
Description
Microsoft OLE DB Driver for SQL Server is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/04/17, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Windows\System32\msoledbsql.dll
Version : 18.7.2.0
93232 - Microsoft Office Compatibility Pack Installed (credentialed check)
-
Synopsis
A compatibility application is installed on the remote host.
Description
Microsoft Office Compatibility Pack, used to enable older versions of Microsoft Office applications to view and edit files created with newer versions of Microsoft Office applications, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0663
Plugin Information
Published: 2016/08/30, Modified: 2025/09/29
Plugin Output

tcp/445/cifs


Office Compatibility Pack is installed with the following components:

Component : Excel Converter
Version : 14.0.6024.1000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Excelcnv.exe

Component : Word Converter
Version : 14.0.4762.1000
Path : C:\Program Files (x86)\Microsoft Office\Office14\Wordconv.exe
27524 - Microsoft Office Detection
-
Synopsis
The remote Windows host contains an office suite.
Description
Microsoft Office is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0505
Plugin Information
Published: 2007/10/23, Modified: 2025/10/14
Plugin Output

tcp/445/cifs


The remote host has the following Microsoft Office 2010 Service Pack 1 components installed :

- ExcelCnv : 14.0.6024.1000
- WordCnv : 14.0.4762.1000
- OneNote : 14.0.6022.1000
- Word : 14.0.6024.1000
- Publisher : 14.0.6026.1000
- PowerPoint : 14.0.6026.1000
- Outlook : 14.0.6025.1000
- Excel : 14.0.6024.1000

92425 - Microsoft Office File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Office on the remote host.
Description
Nessus was able to gather evidence of files that were opened using any Microsoft Office application. The report was extracted from Office MRU (Most Recently Used) registry keys.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
item 37
item 32
item 28
item 15
item 4
item 16
item 48
item 42
item 19
item 10
item 27
item 21
max display
item 34
item 24
item 6
item 50
item 40
item 35
item 31
item 18
item 45
item 49
item 29
item 8
item 2
item 41
item 3
item 43
item 13
item 1
item 38
item 36
item 17
item 11
item 26
item 5
item 20
item 46
item 39
item 30
item 7
item 12
item 23
item 22
item 47
item 44
item 14
item 25
item 9
item 33
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\20122025.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\408_Base Position File.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\45854396.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\all inc 07012026.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\all inc 08012026.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\all inc 09012026.xlsx.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_15122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_16122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_17122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_19122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_22122025 (1).csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_22122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BASEPOSITION_408_23122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Bhavcopy_MCX_CO_0_0_0_20251226_F_0000.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Bhavcopy_MCX_CO_0_0_0_20251229_F_0000.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BSERISK_Delta_20260106-01.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\bulk 16122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\BULK_23122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\COPY OF MTF MARGIN SHORTFALL 12-12-2025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\Downloads.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MCX_ProductMaster.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\mtf var.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MTF_APPROVED_JAN_29122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MTF_VARMARGINREPORT (5).csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MTF_VARMarginReport (5).xls.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MTF_VARMarginReport.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\MTF_VARMarginReport.xls.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\not to do epn 11122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\not to do epn_05012026.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\not to do epn_22122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\not to do epn_26122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\not to do epn_30122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VAR070126.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VAR080126.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VAR151225 (2).csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VAR151225.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VAR151225.xls.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VarFile12122025.csv.LNK
C:\\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\VarFile12122025.xls.LNK
C:\\Users\LKPAdmin\AppData\Roaming\Microsoft\Office\Recent\ClientMarginUtilEQ - 2025-03-17T114213.210.LNK
C:\\Users\LKPAdmin\AppData\Roaming\Microsoft\Office\Recent\index.dat

User AppData recent used file report attached
Office MRU registry report attached.
92361 - Microsoft Office Macros Configuration
-
Synopsis
Nessus was able to collect and report Office macro configuration data for active accounts on the remote host.
Description
Nessus was able to collect Office macro configuration information for active accounts on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Office macros information attached.
77605 - Microsoft OneNote Detection
-
Synopsis
The remote Windows host contains Microsoft OneNote.
Description
Microsoft OneNote is installed on the remote host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0664
Plugin Information
Published: 2014/09/10, Modified: 2025/09/29
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft Office\Office14\OneNote.exe
Version : 14.0.6022.1000
124120 - Microsoft Outlook Attachment Previewing Enabled
-
Synopsis
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Description
Microsoft Outlook application that is installed on the remote host has attachment previewing enabled.
Solution
Disable attachment previewing settings.
Risk Factor
None
Plugin Information
Published: 2019/04/17, Modified: 2019/04/17
Plugin Output

tcp/0

Outlook application in Microsoft Office 2010 has attachment previewing enabled.
92427 - Microsoft Paint Recent File History
-
Synopsis
Nessus was able to enumerate files opened in Microsoft Paint on the remote host.
Description
Nessus was able to generate a list of files opened using the Microsoft Paint program.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Production
- Z:\bcast.png

57033 - Microsoft Patch Bulletin Feasibility Check
-
Synopsis
Nessus is able to check for Microsoft patch bulletins.
Description
Using credentials supplied in the scan policy, Nessus is able to collect information about the software and patches installed on the remote Windows host and will use that information to check for missing Microsoft security updates.

Note that this plugin is purely informational.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/06, Modified: 2021/07/12
Plugin Output

tcp/445/cifs



Nessus is able to test for missing patches using :
Nessus

125835 - Microsoft Remote Desktop Connection Installed
-
Synopsis
A graphical interface connection utility is installed on the remote Windows host
Description
Microsoft Remote Desktop Connection (also known as Remote Desktop Protocol or Terminal Services Client) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/06/12, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Windows\\System32\\mstsc.exe
Version : 10.0.14393.2273

11217 - Microsoft SQL Server Detection (credentialed check)
-
Synopsis
The remote host has a database server installed.
Description
Nessus has detected one or more installs of Microsoft SQL server by examining the registry and file systems on the remote host.
See Also
Solution
Ensure the latest service pack and hotfixes are installed.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 2003/01/26, Modified: 2025/09/24
Plugin Output

tcp/445/cifs


Nessus detected 2 installs of Microsoft SQL Server:

Path : C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn
Version : 13.0.5026.0
arch : x64
instance_name : SQLEXPRESS
is_accessible_share : 1
local_db : 0
localdb : 0

Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Version : 15.0.2000.5
arch : x64
instance_name : MSSQLSERVER
is_accessible_share : 1
local_db : 0
localdb : 0


Nessus detected 3 installs of Microsoft SQL Server:

Version : 13.0.5026.0
Edition : Express Edition
Path : C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn
Named Instance : SQLEXPRESS
Recommended Version : 13.0.6419.1 (2016 GDR (KB5014355)).

Version : 15.0.2000.5
Edition : Standard Edition
Path : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn
Named Instance : MSSQLSERVER

118095 - Microsoft SQL Server Management Studio (SSMS) Installed
-
Synopsis
A SQL Server Management solution is installed on the remote Windows host.
Description
Microsoft SQL Server Management Studio (SSMS) is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0805
Plugin Information
Published: 2018/10/12, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\IDE\
Version : 20.1.10.0

69482 - Microsoft SQL Server STARTTLS Support
-
Synopsis
The remote service supports encrypting traffic.
Description
The remote Microsoft SQL Server service supports the use of encryption initiated during pre-login to switch from a cleartext to an encrypted communications channel.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/07/04, Modified: 2022/04/11
Plugin Output

tcp/1433/mssql


Here is the Microsoft SQL Server's SSL certificate that Nessus
was able to collect after sending a pre-login packet :

------------------------------ snip ------------------------------
Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 76 B1 4A E7 D1 06 80 A2 4A 86 82 7A 7E EF 3F 3B

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 05 01:30:48 2026 GMT
Not Valid After: Jan 05 01:30:48 2056 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 B1 46 55 AC 4A 9E 3F 96 68 7D CF 9D B1 AF D2 64 BD CE E5
51 69 05 4C 11 AB C8 15 9F C9 4C 02 DB 76 DA 84 69 92 3E A0
15 AA 39 EF F6 7C 2C 4C 55 2E FD 5E 30 75 A6 64 31 5F 1F E4
2F 38 E5 F1 B6 08 93 74 7D AA 94 94 97 14 F7 B2 7C D6 6F 03
A7 49 DB F3 05 99 2F 80 4C 0F 5F 7B 7D 9C E4 6F 20 F0 FB A0
F4 76 22 3A 01 C3 0E 00 F5 70 E3 73 3E F3 1A 45 E2 62 9B 60
43 FB AA E5 A3 A0 5D F9 77 3E A3 20 08 BE 26 06 99 D0 3A 98
69 4C 87 02 11 D4 9B 97 82 5C 22 E3 84 3A 08 9F 75 8E DE 15
6E 07 6B 84 8B 26 3C 20 03 A1 13 CC 98 1F 7F 63 73 B1 A8 B0
3A F5 E5 0E 87 10 36 E9 7E 43 6E 97 E9 DA 97 F0 17 3C 7D 1A
A1 F5 AF 3E 4D 75 54 F7 88 A3 D4 AF 19 9A 12 8B B4 63 73 D7
2E 7A BB D4 BC 2F B8 2D 1C 01 AE 81 4B 37 76 75 28 89 4D 03
19 C2 0D 52 B2 C2 78 A3 74 C0 F3 35 62 65 CC BC 07
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 74 36 D8 95 D2 BF 64 8A F3 28 07 63 4F E9 8B DA 97 FB 9A
27 39 D6 DA A1 3E 31 D9 2B 02 F4 3F F4 0B B0 25 72 67 2F F5
0F 87 1A 05 56 E8 51 3D B1 A8 D1 82 E9 C7 88 BC 53 57 DD 3C
4C AB E8 F9 C1 3F BE DA BC 23 F5 0B AC F3 FF 31 6B 9B FA 3B
97 5F A0 56 1B 38 7C 1F 49 61 32 70 D8 DE 2E CA E7 11 82 2B
4D D1 C6 D0 EC 77 94 A6 F2 EE 33 30 BC A0 B7 4D 62 AA E1 EB
C8 AF B1 C1 2F 77 95 93 72 ED 0B 76 7C 28 95 C0 29 56 DC FE
4A F3 5D BD 35 7A 12 E1 6A 63 43 69 A8 81 FD C9 68 A1 E6 47
82 5C 73 5D 58 7E BF C4 50 C2 51 00 C1 7F 6D E8 53 EA 8D FF
2E F2 3C C2 D0 7B 62 C7 BC AA 88 3D B6 93 68 65 AC 1C 36 86
8F BD EA 45 F8 12 C3 E6 D0 2B 38 64 C6 F0 DA A4 EC 19 08 DB
A8 17 4B 15 39 B3 B6 D4 5D B0 82 60 9F 16 3E E9 ED 43 B7 69
E5 F2 E4 10 6E B9 DB F8 79 E9 A7 1B 31 35 8F BC A0


------------------------------ snip ------------------------------


SQL Server Version : 15.0.2000.0
SQL Server Instance : MSSQLSERVER
10144 - Microsoft SQL Server TCP/IP Listener Detection
-
Synopsis
A database server is listening on the remote port.
Description
The remote host is running MSSQL, a database server from Microsoft. It is possible to extract the version number of the remote installation from the server pre-login response.
Solution
Restrict access to the database to allowed IPs only.
Risk Factor
None
References
XREF IAVT:0001-T-0800
Plugin Information
Published: 1999/10/12, Modified: 2024/07/29
Plugin Output

tcp/1433/mssql


Service : mssql-MSSQLSERVER
Version : 15.0.2000.0
InstanceName : MSSQLSERVER
Note : The remote MSSQL server accepts cleartext logins.

10674 - Microsoft SQL Server UDP Query Remote Version Disclosure
-
Synopsis
It is possible to determine the remote SQL server version.
Description
Microsoft SQL server has a function wherein remote users can query the database server for the version that is being run. The query takes place over the same UDP port that handles the mapping of multiple SQL server instances on the same machine.

It is important to note that, after Version 8.00.194, Microsoft decided not to update this function. This means that the data returned by the SQL ping is inaccurate for newer releases of SQL Server.
Solution
If there is only a single SQL instance installed on the remote host, consider filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2001/05/25, Modified: 2018/03/13
Plugin Output

udp/1434


A 'ping' request returned the following information about the remote
SQL instances :

ServerName : XHWAKEYESRV
InstanceName : MSSQLSERVER
IsClustered : No
Version : 15.0.2000.5
tcp : 1433

ServerName : XHWAKEYESRV
InstanceName : SQLEXPRESS
IsClustered : No
Version : 13.2.5026.0

93962 - Microsoft Security Rollup Enumeration
-
Synopsis
This plugin enumerates installed Microsoft security rollups.
Description
Nessus was able to enumerate the Microsoft security rollups installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/10/11, Modified: 2025/11/18
Plugin Output

tcp/445/cifs


Cumulative Rollup : 05_2018
Cumulative Rollup : 04_2018
Cumulative Rollup : 03_2018_2
Cumulative Rollup : 02_2018
Cumulative Rollup : 01_2018
Cumulative Rollup : 12_2017
Cumulative Rollup : 11_2017 [KB4048953]
Cumulative Rollup : 10_2017
Cumulative Rollup : 09_2017
Cumulative Rollup : 08_2017
Cumulative Rollup : 07_2017
Cumulative Rollup : 06_2017
Cumulative Rollup : 05_2017
Cumulative Rollup : 04_2017
Cumulative Rollup : 03_2017
Cumulative Rollup : 01_2017
Cumulative Rollup : 12_2016
Cumulative Rollup : 11_2016
Cumulative Rollup : 10_2016

Latest effective update level : 05_2018
File checked : C:\Windows\system32\ntoskrnl.exe
File version : 10.0.14393.2273
Associated KB : 4103723, 4103720
50346 - Microsoft Update Installed
-
Synopsis
A software updating service is installed.
Description
Microsoft Update, an expanded version of Windows Update, is installed on the remote Windows host. This service provides updates for the operating system and Internet Explorer as well as other Windows software such as Microsoft Office, Exchange, and SQL Server.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/10/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

265694 - Microsoft Visual Studio Tools for Applications Installed (Windows)
-
Synopsis
The remote Windows host has an integrated development environment installed.
Description
Microsoft Visual Studio Tools for Applications (VSTA) is a set of tools that independent software vendors (ISVs) can use to build customization abilities into their applications for both automation and extensibility, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/09/22, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus detected 2 installs of Microsoft Visual Studio Tools for Applications:

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\15.0\Bin\VstaCore.dll
Version : 15.0.27520
product_version : 2017

Path : C:\Program Files\Common Files\Microsoft Shared\VSTA\16.0\Bin\VstaCore.dll
Version : 16.0.31110
product_version : 2019

10902 - Microsoft Windows 'Administrators' Group User List
-
Synopsis
There is at least one user in the 'Administrators' group.
Description
Using the supplied credentials, it is possible to extract the member list of the 'Administrators' group. Members of this group have complete access to the remote system.
Solution
Verify that each member of the group should have this type of access.
Risk Factor
None
Plugin Information
Published: 2002/03/15, Modified: 2018/05/16
Plugin Output

tcp/445/cifs


The following users are members of the 'Administrators' group :

- XHWAKEYESRV\Production (User)
- XHWAKEYESRV\LKPAdmin (User)
- XHWAKEYESRV\tidua (User)
48763 - Microsoft Windows 'CWDIllegalInDllSearch' Registry Setting
-
Synopsis
CWDIllegalInDllSearch Settings: Improper settings could allow code execution attacks.
Description
Windows Hosts can be hardened against DLL hijacking attacks by setting the The 'CWDIllegalInDllSearch' registry entry in to one of the following settings:

- 0xFFFFFFFF (Removes the current working directory from the default DLL search order)

- 1 (Blocks a DLL Load from the current working directory if the current working directory is set to a WebDAV folder)

- 2 (Blocks a DLL Load from the current working directory if the current working directory is set to a remote folder)
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/26, Modified: 2019/12/20
Plugin Output

tcp/445/cifs


Name : SYSTEM\CurrentControlSet\Control\Session Manager\CWDIllegalInDllSearch
Value : Registry Key Empty or Missing

92370 - Microsoft Windows ARP Table
-
Synopsis
Nessus was able to collect and report ARP table information from the remote host.
Description
Nessus was able to collect ARP table information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

172.17.100.10 : 78-64-a0-ba-d1-47
172.17.100.31 : d4-f5-ef-60-4d-20
172.17.100.38 : 00-50-56-88-a7-ac
172.17.100.39 : 00-50-56-bc-4f-46
172.17.100.51 : 00-50-56-88-3c-0d
172.17.100.60 : 00-50-56-bc-47-5e
172.17.100.83 : 00-50-56-bc-b4-9f
172.17.100.88 : 00-50-56-bc-f7-5e
172.17.100.91 : 00-50-56-88-23-83
172.17.100.137 : 00-50-56-bc-37-2c
172.17.100.149 : 00-50-56-93-04-7f
172.17.100.184 : 00-50-56-bc-a7-99
172.17.100.187 : 00-50-56-bc-5f-8c
172.17.100.222 : 24-5e-be-5c-14-77
172.17.100.254 : 1a-c2-41-87-f6-3d
172.17.100.255 : ff-ff-ff-ff-ff-ff
224.0.0.2 : 01-00-5e-00-00-02
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
229.0.0.1 : 01-00-5e-00-00-01
233.1.2.5 : 01-00-5e-01-02-05
239.255.255.250 : 01-00-5e-7f-ff-fa
10.20.30.255 : ff-ff-ff-ff-ff-ff
224.0.0.2 : 01-00-5e-00-00-02
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
229.0.0.1 : 01-00-5e-00-00-01
233.1.2.5 : 01-00-5e-01-02-05
239.255.255.250 : 01-00-5e-7f-ff-fa
10.195.58.131 : 70-bc-48-e2-ac-01
10.195.58.157 : 00-50-56-88-22-c7
10.195.58.190 : 00-50-56-88-b8-a1
10.195.58.191 : ff-ff-ff-ff-ff-ff
224.0.0.2 : 01-00-5e-00-00-02
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
229.0.0.1 : 01-00-5e-00-00-01
233.1.2.5 : 01-00-5e-01-02-05
239.255.70.3 : 01-00-5e-7f-46-03
239.255.255.250 : 01-00-5e-7f-ff-fa
10.113.99.2 : 48-00-b3-f5-bf-01
10.113.99.3 : f4-74-70-cc-26-01
10.113.99.52 : 00-50-56-88-a3-58
10.113.99.255 : ff-ff-ff-ff-ff-ff
224.0.0.2 : 01-00-5e-00-00-02
224.0.0.22 : 01-00-5e-00-00-16
224.0.0.251 : 01-00-5e-00-00-fb
224.0.0.252 : 01-00-5e-00-00-fc
227.0.0.1 : 01-00-5e-00-00-01
228.0.0.2 : 01-00-5e-00-00-02
229.0.0.1 : 01-00-5e-00-00-01
233.1.2.5 : 01-00-5e-01-02-05
239.255.255.250 : 01-00-5e-7f-ff-fa
255.255.255.255 : ff-ff-ff-ff-ff-ff

Extended ARP table information attached.
70615 - Microsoft Windows AutoRuns Boot Execute
-
Synopsis
Report programs that startup associates with session manager subsystem.
Description
Report registry startup locations associated with the session manager subsystem during boot time.

These registry keys start-up with the smss.exe service during boot time and perform system tasks that cannot be performed while Windows is running.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\System\CurrentControlSet\Control\Session Manager\bootexecute
- autocheck autochk /q /v *

70616 - Microsoft Windows AutoRuns Codecs
-
Synopsis
Report programs set to normally start with multimedia.
Description
Codecs are encoders and decoders for digital data streams commonly associated with video and audio playback.

The following keys are codecs that are set to start automatically to control different types of digital media encoding and decoding.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\System32\l3codeca.acm
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
- vidc.yvu9 : tsbyuv.dll
- vidc.mrle : msrle32.dll
- vidc.iyuv : iyuv_32.dll
- wavemapper : msacm32.drv
- msacm.msadpcm : msadp32.acm
- vidc.yuy2 : msyuv.dll
- vidc.uyvy : msyuv.dll
- vidc.msvc : msvidc32.dll
- msacm.imaadpcm : imaadp32.acm
- msacm.msg711 : msg711.acm
- msacm.msgsm610 : msgsm32.acm
- msacm.l3acm : C:\Windows\SysWOW64\l3codeca.acm
- vidc.cvid : iccvid.dll
- vidc.yvyu : msyuv.dll
- midimapper : midimap.dll
- vidc.i420 : iyuv_32.dll


+ HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
+ CLSID : {129D7E40-C10D-11D0-AFB9-00AA00B67A42}
- Name : DV Muxer
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {1643E180-90F5-11CE-97D5-00AA0055595A}
- Name : Color Space Converter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {187463A0-5BB7-11D3-ACBE-0080C75E246E}
- Name : WM ASF Reader
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {1B544C20-FD0B-11CE-8C63-00AA0044B51E}
- Name : AVI Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1DA08500-9EDC-11CF-BC10-00AA00AC74F6}
- Name : VGA 16 Color Ditherer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {1f26a602-2b5c-4b63-b8e8-9ea5c1a7dc2e}
- Name : SBE2MediaTypeProfile
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {212690FB-83E5-4526-8FD7-74478B7939CD}
- Name : Microsoft DTV-DVD Video Decoder
- Value : C:\Windows\System32\msmpeg2vdec.dll

+ CLSID : {280A3020-86CF-11D1-ABE6-00A0C905F375}
- Name : AC3 Parser Filter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {2DB47AE5-CF39-43C2-B4D6-0CD8D90946F4}
- Name : StreamBufferSink
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {301056D0-6DFF-11D2-9EEB-006008039E37}
- Name : MJPEG Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {336475D0-942A-11CE-A870-00AA002FEAB5}
- Name : MPEG-I Stream Splitter
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {33FACFE0-A9BE-11D0-A520-00A0D10129C0}
- Name : SAMI (CC) Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {370A1D5D-DDEB-418C-81CD-189E0D4FA443}
- Name : VBI Codec
- Value : C:\Windows\System32\VBICodec.ax

+ CLSID : {3AE86B20-7BE8-11D1-ABE6-00A0C905F375}
- Name : MPEG-2 Splitter
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {3D07A539-35CA-447C-9B05-8D85CE924F9E}
- Name : Closed Captions Analysis Filter
- Value : C:\Windows\System32\cca.dll

+ CLSID : {3E458037-0CA6-41aa-A594-2AA6C02D709B}
- Name : SBE2FileScan
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {42150CD9-CA9A-4EA5-9939-30EE037F6E74}
- Name : Microsoft MPEG-2 Video Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {48025243-2D39-11CE-875D-00608CB78066}
- Name : Internal Script Command Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4A2286E0-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Audio Decoder
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {4EB31670-9FC6-11CF-AF6E-00AA00B67A42}
- Name : DV Splitter
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {51B4ABF3-748F-4E3B-A276-C828330E926A}
- Name : Video Mixing Renderer 9
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {5F5AFF4A-2F7F-4279-88C2-CD88EB39D144}
- Name : Microsoft MPEG-2 Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {6A08CF80-0E18-11CF-A24D-0020AFD79767}
- Name : ACM Wrapper
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {6CFAD761-735D-4AA5-8AFC-AF91A7D61EBA}
- Name : MPEG-2 Video Stream Analyzer
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {6E8D4A20-310C-11D0-B79A-00AA003767A7}
- Name : Line 21 Decoder
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {6F26A6CD-967B-47FD-874A-7AED2C9D25A2}
- Name : Video Port Manager
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {70E102B0-5556-11CE-97C0-00AA0055595A}
- Name : Video Renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {7B3BC2A0-AA50-4ae7-BD44-B03649EC87C2}
- Name : VPS Decoder
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {7C23220E-55BB-11D3-8B16-00C04FB6BD3D}
- Name : WM ASF Writer
- Value : C:\Windows\System32\qasf.dll

+ CLSID : {814B9800-1C88-11D1-BAD9-00609744111A}
- Name : VBI Surface Allocator
- Value : %SystemRoot%\System32\vbisurf.ax

+ CLSID : {8596E5F0-0DA5-11D0-BD21-00A0C911CE86}
- Name : File writer
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {9B8C4620-2C1A-11D0-8493-00A02438AD48}
- Name : DVD Navigator
- Value : C:\Windows\System32\qdvd.dll

+ CLSID : {A0025E90-E45B-11D1-ABE9-00A0C905F375}
- Name : Overlay Mixer2
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {A888DF60-1E90-11CF-AC98-00AA004C0FA9}
- Name : AVI Draw
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {ACD453BC-C58A-44D1-BBF5-BFB325BE2D78}
- Name : Microsoft MPEG-2 Audio Encoder
- Value : C:\Windows\System32\msmpeg2enc.dll

+ CLSID : {AD6C8934-F31B-4F43-B5E4-0541C1452F6F}
- Name : WST Pager
- Value : C:\Windows\System32\WSTPager.ax

+ CLSID : {AFB6C280-2C41-11D3-8A60-0000F81E0E4A}
- Name : MPEG-2 Demultiplexer
- Value : C:\Windows\System32\mpg2splt.ax

+ CLSID : {B1B77C00-C3E4-11CF-AF79-00AA00B67A42}
- Name : DV Video Decoder
- Value : C:\Windows\System32\qdv.dll

+ CLSID : {C1F400A0-3F08-11D3-9F0B-006008039E37}
- Name : SampleGrabber
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C1F400A4-3F08-11D3-9F0B-006008039E37}
- Name : Null Renderer
- Value : C:\Windows\System32\qedit.dll

+ CLSID : {C666E115-BB62-4027-A113-82D643FE2D99}
- Name : MPEG-2 Sections and Tables
- Value : C:\Windows\System32\Mpeg2Data.ax

+ CLSID : {C9F5FE02-F851-4EB5-99EE-AD602AF1E619}
- Name : StreamBufferSource
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {CC58E280-8AA1-11D1-B3F1-00AA003761C5}
- Name : Smart Tee
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {CD8743A1-3736-11D0-9E69-00C04FD7C15B}
- Name : Overlay Mixer
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {CF49D4E0-1115-11CE-B03A-0020AF0BA770}
- Name : AVI Decompressor
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D3588AB0-0781-11CE-B03A-0020AF0BA770}
- Name : AVI/WAV File Source
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A1-7548-11CF-A520-0080C77EF58A}
- Name : Wave Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A2-7548-11CF-A520-0080C77EF58A}
- Name : MIDI Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A3-7548-11CF-A520-0080C77EF58A}
- Name : Multi-file Parser
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {D51BD5A5-7548-11CF-A520-0080C77EF58A}
- Name : File stream renderer
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E2448508-95DA-4205-9A27-7EC81E723B1A}
- Name : StreamBufferSink2
- Value : C:\Windows\System32\sbe.dll

+ CLSID : {E2510970-F137-11CE-8B67-00AA00A3F1A6}
- Name : AVI Mux
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {E4206432-01A1-4BEE-B3E1-3702C8EDC574}
- Name : Line 21 Decoder 2
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB5-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (Async.)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {E436EBB6-524F-11CE-9F53-0020AF0BA770}
- Name : File Source (URL)
- Value : C:\Windows\System32\quartz.dll

+ CLSID : {F8388A40-D5BB-11D0-BE5A-0080C706568E}
- Name : Infinite Pin Tee Filter
- Value : C:\Windows\System32\qcap.dll

+ CLSID : {FA10746C-9B63-4B6C-BC49-FC300EA5F256}
- Name : Enhanced Video Renderer
- Value : C:\Windows\System32\evr.dll

+ CLSID : {FC772AB0-0C7F-11D3-8FF2-00A0C9224CF4}
- Name : BDA MPEG2 Transport Information Filter
- Value : C:\Windows\System32\psisrndr.ax

+ CLSID : {FEB50740-7BEF-11CE-9BD9-0000E202599C}
- Name : MPEG Video Decoder
- Value : C:\Windows\System32\quartz.dll


+ HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


+ HKLM\Software\Wow6432Node\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
+ CLSID : {5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
- Name : Microsoft Camera Raw Decoder
- Value : C:\Windows\System32\WindowsCodecsRaw.dll


70617 - Microsoft Windows AutoRuns Explorer
-
Synopsis
Reports programs that startup associates with the explorer process.
Description
Report the startup locations associated with the explorer.exe process.

These items could add controls to menus, add extensions for common protocols such as HTTP or FTP, or set control user activity with the desktop and control panels.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Protocols\Filter
+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/octet-stream
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-complus
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
- Name : application/x-msdownload
- Value : C:\Windows\System32\mscoree.dll

+ CLSID : {807573E5-5146-11D5-A672-00B0D022E945}
- Name : text/xml
- Value : C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL


+ HKLM\SOFTWARE\Classes\Protocols\Handler
+ CLSID : {3050F406-98B5-11CF-BB82-00AA00BDCE0B}
- Name : about
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {3dd53d40-7b8b-11D0-b013-00aa0059ce02}
- Name : cdl
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {12D51199-0DB5-46FE-A120-47A3D7D937CC}
- Name : dvd
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : file
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e3-baf9-11ce-8c82-00aa004ba90b}
- Name : ftp
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1}
- Name : hpapp
- Value : C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll

+ CLSID : {79eac9e2-baf9-11ce-8c82-00aa004ba90b}
- Name : http
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {79eac9e5-baf9-11ce-8c82-00aa004ba90b}
- Name : https
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : javascript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {79eac9e7-baf9-11ce-8c82-00aa004ba90b}
- Name : local
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}
- Name : mailto
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {05300401-BCBC-11d0-85E3-00C04FD85AB4}
- Name : mhtml
- Value : C:\Windows\System32\inetcomm.dll

+ CLSID : {79eac9e6-baf9-11ce-8c82-00aa004ba90b}
- Name : mk
- Value : C:\Windows\System32\urlmon.dll

+ CLSID : {314111c7-a502-11d2-bbca-00c04f8ec294}
- Name : ms-help
- Value :

+ CLSID : {9D148291-B9C8-11D0-A4CC-0000F80149F6}
- Name : ms-its
- Value : C:\Windows\System32\itss.dll

+ CLSID : {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
- Name : res
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : tbauth
- Value : C:\Windows\System32\tbauth.dll

+ CLSID : {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
- Name : tv
- Value : C:\Windows\System32\msvidctl.dll

+ CLSID : {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}
- Name : vbscript
- Value : C:\Windows\System32\mshtml.dll

+ CLSID : {14654CA6-5711-491D-B89A-58E571679951}
- Name : windows.tbauth
- Value : C:\Windows\System32\tbauth.dll


+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CLSID : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- Name : webcheck
- Value :


+ HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcaseMenu
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {09799AFB-AD67-11d1-ABCD-00C04FC30936}
- Name : Open With
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : Open With EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {90AA3A4E-1CBA-4233-B8BB-535773D48449}
- Name : Taskband Pin
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcasePage
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {7444C719-39BF-11D1-8CD9-00C04FC29D45}
- Name : CryptoSignMenu
- Value : %SystemRoot%\system32\cryptext.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {3EA48300-8CF6-101B-84FB-666CCB9BCD32}
- Name : OLE DocFile Property Page
- Value : %SystemRoot%\system32\docprop.dll

+ CLSID : {883373C3-BF89-11D1-BE35-080036B11A03}
- Name : Summary Properties Page
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
+ CLSID : {f3d06e7c-1e45-4a26-847e-f9fcdee59be0}
- Name : CopyAsPathMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {7BA4C740-9E81-11CF-99D3-00AA004AE837}
- Name : SendTo
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name :
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\AllFileSystemObjects\ShellEx\PropertySheetHandlers
+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name :
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
+ CLSID : {A470F8CF-A1E8-4f65-8335-227475AA5C46}
- Name : EncryptionMenu
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll


+ HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers
+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll

+ CLSID : {1f2e5c40-9550-11ce-99d2-00aa006e086c}
- Name :
- Value : %SystemRoot%\system32\rshx32.dll

+ CLSID : {4a7ded0a-ad25-11d0-98a8-0800361b1103}
- Name :
- Value : %SystemRoot%\system32\mydocs.dll

+ CLSID : {596AB062-B4D2-4215-9F74-E9109B0A8153}
- Name :
- Value : %SystemRoot%\system32\twext.dll

+ CLSID : {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
- Name :
- Value : C:\Windows\System32\DfsShlEx.dll

+ CLSID : {ef43ecfe-2ab9-4632-bf21-58909dd177f0}
- Name :
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers
+ CLSID : {217FC9C0-3AEA-1069-A2DB-08002B30309D}
- Name : FileSystem
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
+ CLSID : {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- Name : New
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
- Name : Sharing
- Value : %SystemRoot%\system32\ntshrui.dll


+ HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcaseMenu
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {AE81D5A2-A34B-4D93-8DF8-540DBCE48043}
- Name : Kaspersky Anti-Virus 21.15
- Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\x64\shellex.dll

+ CLSID : {3dad6c5d-2167-4cae-9914-f99e41c12cfa}
- Name : Library Location
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {474C98EE-CF3D-41f5-80E3-4AAB0AB04301}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll

+ CLSID : {470C0EBD-5D73-4d58-9CED-E91E22E23282}
- Name : PintoStartScreen
- Value : %SystemRoot%\system32\shell32.dll

+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
- Name : Start Menu Pin
- Value : %SystemRoot%\system32\shell32.dll


+ HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers
+ CLSID : {B41DB860-64E4-11D2-9906-E49FADC173CA}
- Name : WinRAR
- Value : C:\Program Files\WinRAR\rarext.dll

+ CLSID : {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- Name : WinRAR32
- Value :

+ CLSID : {BD472F60-27FA-11cf-B8B4-444553540000}
- Name :
- Value : %SystemRoot%\system32\zipfldr.dll


+ HKLM\Software\Classes\Folder\ShellEx\PropertySheetHandlers
+ CLSID : {85BBD920-42A0-1069-A2E4-08002B30309D}
- Name : BriefcasePage
- Value : %SystemRoot%\system32\syncui.dll

+ CLSID : {7EFA68C6-086B-43e1-A2D2-55A113531240}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


+ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
+ CLSID : {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
- Name : EnhancedStorageShell
- Value : C:\Windows\System32\EhStorShell.dll

+ CLSID : {4E77131D-3629-431c-9818-C5679DC83E81}
- Name : Offline Files
- Value : %SystemRoot%\System32\cscui.dll


70619 - Microsoft Windows AutoRuns Internet Explorer
-
Synopsis
Report programs that startup associates with Internet Explorer.
Description
Report registry startup locations associated with the Internet Explorer (IE) application.

The startup values include Internet Explorer plugins to extend the functionality of IE, browser toolbars, hooks into browser controls, and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- Value : C:\Program Files\Java\jre-1.8\bin\ssv.dll

+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL

+ CLSID : {DBC80044-A445-435b-BC74-9C25C1C588A9}
- Value : C:\Program Files\Java\jre-1.8\bin\jp2ssv.dll


HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ CLSID : {B4F3A835-0E21-4959-BA22-42B3008E02FF}
- Name : URLRedirectionBHO
- Value : C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL


HKLM\Software\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
+ CLSID : {2670000A-7350-4f3c-8081-5663EE0C6C49}
- Value : CLSID is not set in HKCR\CLSID\

+ CLSID : {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- Value : CLSID is not set in HKCR\CLSID\


70620 - Microsoft Windows AutoRuns Known DLLs
-
Synopsis
DLLs listed to be shared by processes.
Description
The known DLLs registry setting is used to define DLLs that are shared between processes without a process having to search for the DLL location.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
- imagehlp : IMAGEHLP.dll
- _wow64win : Wow64win.dll
- oleaut32 : OLEAUT32.dll
- normaliz : NORMALIZ.dll
- msvcrt : MSVCRT.dll
- shell32 : SHELL32.dll
- msctf : MSCTF.dll
- gdi32 : gdi32.dll
- nsi : NSI.dll
- advapi32 : advapi32.dll
- coml2 : coml2.dll
- clbcatq : clbcatq.dll
- shlwapi : SHLWAPI.dll
- psapi : PSAPI.DLL
- lpk : LPK.dll
- imm32 : IMM32.dll
- combase : combase.dll
- _wow64 : Wow64.dll
- user32 : user32.dll
- sechost : sechost.dll
- _wow64cpu : Wow64cpu.dll
- rpcrt4 : rpcrt4.dll
- kernel32 : kernel32.dll
- ws2_32 : WS2_32.dll
- wldap32 : WLDAP32.dll
- ole32 : ole32.dll
- difxapi : difxapi.dll
- setupapi : Setupapi.dll
- comdlg32 : COMDLG32.dll
- gdiplus : gdiplus.dll
70613 - Microsoft Windows AutoRuns LSA Providers
-
Synopsis
Programs set to start as Local Security Authority.
Description
An LSA (Local Security Authority) is an application that can be used to authorize users to their systems. The reported autoruns are available to provide this service or features to this service.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0



+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\authentication packages
- msv1_0


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\notification packages
- rassfm
- scecli


+ HKLM\SYSTEM\CurrentControlSet\Control\Lsa\security packages
- ""
70621 - Microsoft Windows AutoRuns Logon
-
Synopsis
Report programs that start-up from the most common registry locations.
Description
Report the most common startup locations used by programs. These are commonly associated with programs that start automatically when the computer is turned on, users log in, users log off, or remote sessions are started.

Such keys can be set from a program install, GPO, or through a malicious process to maintain persistence.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd
- rdpclip


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
- C:\Windows\system32\userinit.exe


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\vmapplet
- SystemPropertiesPerformance.exe /pagefile


+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
- explorer.exe


+ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
- AlternateShell : cmd.exe


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
- Name : sunjavaupdatesched
- Value : "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"


+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {2C7339CF-2B09-4501-B3F3-F3508C9228ED}
- Name : Themes Setup
- Value : /UserInstall

+ CLSID : {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
- Name : Microsoft Windows
- Value : "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE

+ CLSID : {49210152-871f-4ffa-961d-a172abcbc09d}
- Name : Google Platform Experience Helper
- Value : "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4340}
- Name : Windows Desktop Update
- Value : U

+ CLSID : {89820200-ECBD-11cf-8B85-00AA005B4383}
- Name : Web Platform Customizations
- Value : C:\Windows\System32\ie4uinit.exe -UserConfig

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install

+ CLSID : {8A69D345-D564-463c-AFF1-A69D9E530F96}
- Name : Google Chrome
- Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.170\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable

+ CLSID : {A509B1A7-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin

+ CLSID : {A509B1A8-37EF-4b3f-8CFC-4F3A74704073}
- Name : Applying Enhanced Security Configuration
- Value : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser


+ HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
+ CLSID : >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /ShowWMP

+ CLSID : {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
- Name : Microsoft Windows
- Value : "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE

+ CLSID : {6BF52A52-394A-11d3-B153-00C04F79FAA6}
- Name : Microsoft Windows Media Player
- Value : %SystemRoot%\system32\unregmp2.exe /FirstLogon

+ CLSID : {89B4C1CD-B018-4511-B0A1-5476DBF70820}
- Name :
- Value : C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install


+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
- iconservicelib : IconCodecService.dll
- Load :



HKU : \Users\Administrator : S-1-5-21-3119273522-2427777209-1705870880-500

+ HKU\S-1-5-21-3119273522-2427777209-1705870880-500\Software\Microsoft\Windows\CurrentVersion\Run
- Name : apachetomcatmonitor9.0_tomcat9
- Value : "D:\XTPL\Tomcat\bin\Tomcat9w.exe" //MS//Tomcat9

70622 - Microsoft Windows AutoRuns Network Providers
-
Synopsis
Report programs set to automatically start-up as a Network Provider.
Description
The DLLs listed under the registry key are used to provide network services for new protocols.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- RDPNP : %SystemRoot%\System32\drprov.dll

+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\HwOrder\ProviderOrder
- LanmanWorkstation : %SystemRoot%\System32\ntlanman.dll
- RDPNP : %SystemRoot%\System32\drprov.dll
70623 - Microsoft Windows AutoRuns Print Monitor
-
Synopsis
Report programs set to start automatically as a print monitor.
Description
Report the DLLs that control print monitor functions for multiple programs and systems.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0

+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- Local Port : localspl.dll
- Standard TCP/IP Port : tcpmon.dll
- USB Monitor : usbmon.dll
- WSD Port : WSDMon.dll
70618 - Microsoft Windows AutoRuns Registry Hijack Possible Locations
-
Synopsis
Report common registry keys used to hijack execution.
Description
Report common registry keys that can be used to hijack system process execution.

These registry keys can be used to either replace execution or shim a process in the middle of execution to hijack control. Confirm that everything listed here is set to the appropriate settings and that it doesn't look like another process is taking control of the process's execution.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command
- Command : "%1" %*


+ HKLM\Software\Classes\.exe : exefile
- open : "%1" %*
- runas : "%1" %*
- runasuser :


+ HKLM\Software\Classes\.cmd : cmdfile
- edit : %SystemRoot%\System32\NOTEPAD.EXE %1
- open : "%1" %*
- print : %SystemRoot%\System32\NOTEPAD.EXE /p %1
- runas : %SystemRoot%\System32\cmd.exe /C "%1" %*
- runasuser :


+ HKLM\Software\Classes\.htm : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.html : htmlfile
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
- open : "C:\Program Files\Internet Explorer\iexplore.exe" %1
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1
- printto : "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.doc : Word.Document.8
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.docx : Word.Document.12
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vu "%1"
- New : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n /f "%1"
- OnenotePrintto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /h /n "%1"
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /i "%1"
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /j "%1" "%2"
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /vp "%1"


+ HKLM\Software\Classes\.vbs : VBSFile
- Edit : "%SystemRoot%\System32\Notepad.exe" %1
- Open : "%SystemRoot%\System32\WScript.exe" "%1" %*
- Open2 : "%SystemRoot%\System32\CScript.exe" "%1" %*
- Print : "%SystemRoot%\System32\Notepad.exe" /p %1


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"


+ HKLM\Software\Classes\.xls : Excel.Sheet.8
- Edit : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- New : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde /n
- Open : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- OpenAsReadOnly : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /h /dde
- Print : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- Printto : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
- ViewProtected : "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde


+ HKLM\Software\Classes\.xml : xmlfile
- edit : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb edit "%1"
- open : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "%1"


+ HKLM\Software\Classes\.pif : piffile
- open : "%1" %*


+ HKLM\Software\Classes\.txt : txtfile
- open : %SystemRoot%\system32\NOTEPAD.EXE %1
- print : %SystemRoot%\system32\NOTEPAD.EXE /p %1
- printto : %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4"



70624 - Microsoft Windows AutoRuns Report
-
Synopsis
Generate a CSV report of all autoruns.
Description
Collect all autoruns listed in the Windows autoruns plugins and report the primary content in a CSV report.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+Enabled Autoruns Detection Types
- LSA Provider
- Boot Execute
- WinLogon
- Known DLLs
- Winsock Provider
- Service
- Explorer
- Logon
- Codecs
- Driver
- Image Hijack
- Network Provider
- Scheduled Tasks
- Print Monitor
- Internet Explorer


The attached CSV contains information about Windows autoruns.
70625 - Microsoft Windows AutoRuns Scheduled Tasks
-
Synopsis
Report processes that start-up via the scheduled task manager.
Description
This plugin lists the scheduled tasks for the system. The scheduled tasks are often used to update software, for systems administrators to run processes, and can be used by malware to spread on systems.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ Task
+ RegistrationInfo
- Author : XHWAKEYESRV\Production
- Description : Updates out-of-date system feeds.
- URI : \User_Feed_Synchronization-{F5C8AA20-23A8-4456-863A-D35849641954}
+ Principals
+ Principal
- UserId : S-1-5-21-3119273522-2427777209-1705870880-500
- LogonType : InteractiveToken
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2026-01-10T11:25:35+05:30
- EndBoundary : 2036-01-10T11:25:35+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : C:\Windows\system32\msfeedssync.exe
- Arguments : sync

+ Task
+ RegistrationInfo
- Author : NT AUTHORITY\SYSTEM
- Description : GoogleUpdater Task System 144.0.7547.4
- URI : \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.4{BDC3A692-704E-4620-8B11-B204B4E3A4E1}
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
+ Triggers
+ LogonTrigger
+ CalendarTrigger
- StartBoundary : 2025-12-12T17:08:45+05:30
+ Repetition
- Interval : PT1H
- Duration : P1D
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe"
- Arguments : --wake --system

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {84F0FAE1-C27B-4F6F-807B-28CF6F96287D}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {429BC048-379E-45E0-80E4-EB1977941B5C}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {613FBA38-A3DF-4AB8-9674-5604984A299A}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2010-09-30T14:53:37.9516706
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- WakeToRun : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ IdleTrigger
+ Actions
+ ComHandler
- ClassId : {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E}
- Data : /RuntimeWide

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6002)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2006-11-09T03:00:00
- RandomDelay : PT1H
+ ScheduleByDay
- DaysInterval : 1
+ LogonTrigger
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {CF2CF428-325B-48D3-8CA8-7633E36E5A32}

+ Task
+ RegistrationInfo
- Date : 2006-11-10T14:29:55.5851926
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Author : $(@%systemRoot%\System32\msdrm.dll,-6001)
- Description : $(@%systemRoot%\System32\msdrm.dll,-6003)
- URI : \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
+ Principals
+ Principal
- GroupId : S-1-1-0
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {BF5CB148-7C77-4D8A-A53E-D81C70CF743C}

+ Task
+ RegistrationInfo
- Date : 2015-02-09T10:54:13.9629482
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-2978287140-3787137133-1749738600-1988163579-2060695581)
- Source : $(@%SystemRoot%\system32\ApplockerCsp.dll,-101)
- Author : $(@%SystemRoot%\system32\ApplockerCsp.dll,-100)
- Description : $(@%SystemRoot%\system32\ApplockerCsp.dll,-102)
- URI : \Microsoft\Windows\AppID\EDP Policy Manager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7588BCA328009213
+ WnfStateChangeTrigger
- StateName : 75E0BCA328009213
+ Actions
+ ComHandler
- ClassId : {DECA92E0-AF85-439E-9204-86679978DA08}
- Data : EdpPolicyManager

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-300)
- Author : $(@%systemroot%\system32\appidsvc.dll,-301)
- Description : $(@%systemroot%\system32\appidsvc.dll,-302)
- URI : \Microsoft\Windows\AppID\PolicyConverter
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\appidpolicyconverter.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\apprepsync.dll,-701)
- Author : $(@%systemroot%\system32\apprepsync.dll,-700)
- Description : $(@%systemroot%\system32\apprepsync.dll,-702)
- URI : \Microsoft\Windows\AppID\SmartScreenSpecific
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ LogonTrigger
- Delay : PT30M
+ Actions
+ ComHandler
- ClassId : {9F2B0085-9218-42A1-88B0-9F0E65851666}
- Data : U

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;CI;FA;;;LS)(A;CI;FA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)
- Source : $(@%systemroot%\system32\appidsvc.dll,-200)
- Author : $(@%systemroot%\system32\appidsvc.dll,-201)
- Description : $(@%systemroot%\system32\appidsvc.dll,-202)
- URI : \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : Queue
- Priority : 10
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT3M
- WaitTimeout : PT23H
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Repetition
- Interval : P1D
+ Actions
+ Exec
- Command : %windir%\system32\appidcertstorecheck.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\appraiser.dll,-500)
- Author : $(@%SystemRoot%\system32\appraiser.dll,-501)
- Description : $(@%SystemRoot%\system32\appraiser.dll,-502)
- URI : \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\invagent.dll,-701)
- Author : $(@%SystemRoot%\system32\invagent.dll,-701)
- Description : $(@%SystemRoot%\system32\invagent.dll,-702)
- URI : \Microsoft\Windows\Application Experience\ProgramDataUpdater
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1DT12H
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\compattelrunner.exe
- Arguments : -maintenance

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;LA)(A;OICI;FA;;;SY)(A;OICI;FRFX;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Author : $(@%SystemRoot%\system32\Startupscan.dll,-701)
- Description : $(@%SystemRoot%\system32\Startupscan.dll,-702)
- URI : \Microsoft\Windows\Application Experience\StartupAppTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
- Priority : 4
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P2D
- Deadline : P3D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Startupscan.dll,SusRunTask

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierdaily
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2016-04-11T03:00:00
- ExecutionTimeLimit : PT5M
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;BA)(A;;FRFX;;;AU)(A;;FRFX;;;IU)
- Source : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10005)
- Author : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10004)
- Description : $(@%systemroot%\system32\AppHostRegistrationVerifier.exe,-10002)
- URI : \Microsoft\Windows\ApplicationData\appuriverifierinstall
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT15M
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2016-04-11T03:00:00
- ExecutionTimeLimit : PT5M
+ ScheduleByWeek
- WeeksInterval : 1
+ DaysOfWeek
+ Saturday
+ WnfStateChangeTrigger
- Delay : PT3M
- StateName : 7508BCA32C7C8741
+ Actions
+ Exec
- Command : %windir%\system32\AppHostRegistrationVerifier.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5001)
- Author : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5002)
- Description : $(@%systemroot%\system32\Windows.Storage.ApplicationData.dll,-5003)
- URI : \Microsoft\Windows\ApplicationData\CleanupTemporaryState
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : Windows.Storage.ApplicationData.dll,CleanupTemporaryState

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%systemroot%\system32\dssvc.dll,-10005)
- Author : $(@%systemroot%\system32\dssvc.dll,-10004)
- Description : $(@%systemroot%\system32\dssvc.dll,-10006)
- URI : \Microsoft\Windows\ApplicationData\DsSvcCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\dstokenclean.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;GA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- URI : \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT15M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ LogonTrigger
- Delay : PT1H
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask

+ Task
+ RegistrationInfo
- Source : $(@%systemroot%\system32\acproxy.dll,-100)
- Author : $(@%systemroot%\system32\acproxy.dll,-101)
- Description : $(@%systemroot%\system32\acproxy.dll,-102)
- URI : \Microsoft\Windows\Autochk\Proxy
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : P365D
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT30M
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : /d acproxy.dll,PerformAutochkOperations

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%SystemRoot%\system32\BthUdTask.exe,-1002)
- Description : $(@%SystemRoot%\system32\BthUdTask.exe,-1001)
- URI : \Microsoft\Windows\Bluetooth\UninstallDeviceTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : BthUdTask.exe
- Arguments : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-103)
- URI : \Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : AIKCertEnroll

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-104)
- URI : \Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7530BCA323098541
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : CryptoPolicy

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;NS)
- Source : $(@%SystemRoot%\system32\ngctasks.dll,-101)
- Author : $(@%SystemRoot%\system32\ngctasks.dll,-100)
- Description : $(@%SystemRoot%\system32\ngctasks.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA323098541
+ WnfStateChangeTrigger
- Delay : PT10M
- StateName : 7520BCA323098541
+ WnfStateChangeTrigger
- StateName : 75C0BCA33E06830D
+ LogonTrigger
- Enabled : false
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {47E30D54-DAC1-473A-AFF7-2355BF78881F}
- Data : NGCKeyPregen

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\SystemTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ RegistrationTrigger
+ BootTrigger
- Delay : PT10S
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : F510BCA32A1E890D
+ RegistrationTrigger
+ LogonTrigger
+ Repetition
- Interval : PT8H
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : USER

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFW;;;IU)
- Source : $(@%SystemRoot%\system32\dimsjob.dll,-100)
- Author : $(@%SystemRoot%\system32\dimsjob.dll,-101)
- Description : $(@%SystemRoot%\system32\dimsjob.dll,-102)
- URI : \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ RestartOnFailure
- Count : 5
- Interval : PT1M
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ SessionStateChangeTrigger
- StateChange : SessionLock
+ SessionStateChangeTrigger
- StateChange : SessionUnlock
+ Actions
+ ComHandler
- ClassId : {58FB76B9-AC85-4E55-AC04-427593B1D060}
- Data : KEYROAMING

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\pstask.dll,-100)
- Author : $(@%systemroot%\system32\pstask.dll,-101)
- Description : $(@%systemroot%\system32\pstask.dll,-102)
- URI : \Microsoft\Windows\Chkdsk\ProactiveScan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CF4270F5-2E43-4468-83B3-A8C45BB33EA1}

+ Task
+ RegistrationInfo
- Date : 2014-01-01T00:00:00
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)(A;;FA;;;S-1-5-80-65843127-2189646064-2697706863-2125155322-3141006483)(A;;FR;;;S-1-5-87-1452649159-2109950929-2856838567-3638795029-1283063528)
- Source : $(@%SystemRoot%\system32\ClipUp.exe,-102)
- Author : $(@%SystemRoot%\system32\ClipUp.exe,-100)
- Description : $(@%SystemRoot%\system32\ClipUp.exe,-101)
- URI : \Microsoft\Windows\Clip\License Validation
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %SystemRoot%\system32\ClipUp.exe
- Arguments : -p -s -o

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- URI : \Microsoft\Windows\CloudExperienceHost\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E4544ABA-62BF-4C54-AAB2-EC246342626C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)
- Source : $(@%systemRoot%\system32\wsqmcons.exe,-106)
- Author : $(@%systemRoot%\system32\wsqmcons.exe,-108)
- Description : $(@%systemRoot%\system32\wsqmcons.exe,-107)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2004-01-02T00:00:00
+ Repetition
- Interval : PT6H
+ Actions
+ Exec
- Command : %SystemRoot%\System32\wsqmcons.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SDFRFX;;;LS)
- Source : $(@%SystemRoot%\system32\kernelceip.dll,-601)
- Author : $(@%SystemRoot%\system32\kernelceip.dll,-600)
- Description : $(@%SystemRoot%\system32\kernelceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
+ Principals
+ Principal
- UserId : S-1-5-19
+ RequiredPrivileges
- Privilege : SeChangeNotifyPrivilege
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 1
- Interval : PT45M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {E7ED314F-2816-4C26-AEB5-54A34D02404C}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SD;;;S-1-5-87-1060603329-121822201-3452730971-4292368946-61207722)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\usbceip.dll,-601)
- Author : $(@%SystemRoot%\system32\usbceip.dll,-600)
- Description : $(@%SystemRoot%\system32\usbceip.dll,-602)
- URI : \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C27F6B1D-FE0B-45E4-9257-38799FA69BC8}
- Data : SYSTEM

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-602)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2011-01-01T23:00:00
- RandomDelay : P7D
+ ScheduleByWeek
- WeeksInterval : 4
+ DaysOfWeek
+ Saturday
+ BootTrigger
- Enabled : false
- Delay : PT1H
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\discan.dll,-601)
- Author : $(@%systemroot%\system32\discan.dll,-600)
- Description : $(@%systemroot%\system32\discan.dll,-603)
- URI : \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7508BCA32907950A
+ Actions
+ ComHandler
- ClassId : {DCFD3EA8-D960-4719-8206-490AE315F94F}
- Data : -CrashRecovery

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\defragsvc.dll,-800)
- Author : $(@%systemroot%\system32\defragsvc.dll,-801)
- Description : $(@%systemroot%\system32\defragsvc.dll,-802)
- URI : \Microsoft\Windows\Defrag\ScheduledDefrag
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -k -g -$

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- URI : \Microsoft\Windows\Device Information\Device
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P4D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-09-01T03:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 750CBCA3290B9641
- Data : 01
+ Actions
+ Exec
- Command : %windir%\system32\devicecensus.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-601)
- Author : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-600)
- Description : $(@%SystemRoot%\System32\DeviceSetupManager.dll,-602)
- URI : \Microsoft\Windows\Device Setup\Metadata Refresh
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {23C1F3CF-C110-4512-ACA9-7B6174ECE888}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\sdiagschd.dll,-102)
- Author : $(@%systemroot%\system32\sdiagschd.dll,-101)
- Description : $(@%systemroot%\system32\sdiagschd.dll,-103)
- URI : \Microsoft\Windows\Diagnosis\Scheduled
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {C1F85EF8-BCC2-4606-BB39-70C523715EB3}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Author : $(@%systemroot%\system32\cleanmgr.exe,-1300)
- Description : $(@%systemroot%\system32\cleanmgr.exe,-1301)
- URI : \Microsoft\Windows\DiskCleanup\SilentCleanup
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\cleanmgr.exe
- Arguments : /autoclean /d %systemdrive%

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-119)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : dfdts.dll,DfdGetDefaultPolicyAndSMART

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\System32\DFDTS.dll,-100)
- Author : $(@%SystemRoot%\System32\DFDTS.dll,-101)
- Description : $(@%SystemRoot%\System32\DFDTS.dll,-118)
- URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\DFDWiz.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\Diagnostics
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\disksnapshot.exe
- Arguments : -z

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\DiskFootprint\StorageSense
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {AB2A519B-03B0-43CE-940A-A73DF850B49A}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP App Launch Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3508BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {35EF4182-F900-4632-B072-8639E4478A61}
- Data : AppLaunch

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\EDP\EDP Auth Task
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 3538BCA3280A9641
+ Actions
+ ComHandler
- ClassId : {35EF4182-F900-4632-B072-8639E4478A61}
- Data : ReAuth

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-600)
- Description : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-601)
- URI : \Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1M
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1B9611
+ Actions
+ ComHandler
- ClassId : {FE285C8C-5360-41C1-A700-045501C740DE}

+ Task
+ RegistrationInfo
- Author : $(@%systemroot%\system32\ErrorDetailsUpdate.dll,-600)
- Description : $(@%SystemRoot%\system32\ErrorDetailsUpdate.dll,-601)
- URI : \Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2H
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9CDA66BE-3271-4723-8D35-DD834C58AD92}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-602)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Installation
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT15M
+ Repetition
- Interval : P1D
+ IdleTrigger
+ Repetition
- Interval : P1D
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Install $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-601)
- Author : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-600)
- Description : $(@%systemRoot%\System32\LanguageComponentsInstaller.Dll,-603)
- URI : \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE}
- Data : Uninstall

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GRGX;;;SU)
- Source : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TempSignedLicenseExchangeTask.dll,-602)
- URI : \Microsoft\Windows\License Manager\TempSignedLicenseExchange
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P7D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {77646A68-AD14-4D53-897D-7BE4DDE5F929}

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\system32\LocationNotificationWindows.exe,-102)
- URI : \Microsoft\Windows\Location\Notifications
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA321089541
- Data : 01
+ Actions
+ Exec
- Command : %windir%\System32\LocationNotificationWindows.exe

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Description : $(@%systemRoot%\System32\WindowsActionDialog.exe,-102)
- URI : \Microsoft\Windows\Location\WindowsActionDialog
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7548BCA321089541
+ Actions
+ Exec
- Command : %windir%\System32\WindowsActionDialog.exe

+ Task
+ RegistrationInfo
- Date : 2008-02-25T19:15:00
- SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\winsatapi.dll,-113)
- Author : $(@%systemroot%\system32\winsatapi.dll,-112)
- Description : $(@%systemroot%\system32\winsatapi.dll,-114)
- URI : \Microsoft\Windows\Maintenance\WinSAT
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT30M
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P1M
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {A9A33436-678B-4C9C-A211-7CC38785E79D}

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapstoasttask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapstoasttask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsToastTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5S
- Hidden : true
- MultipleInstancesPolicy : Queue
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {9885AEF2-BD9F-41E0-B15E-B3141395E803}
- Data : $(Arg0);$(Arg1);$(Arg2);$(Arg3)

+ Task
+ RegistrationInfo
- Date : 2014-11-05T00:00:00
- SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-955107200-3701964851-1150726376)(A;;FRFX;;;NS)(A;;FRFX;;;AU)
- Author : $(@%SystemRoot%\system32\mapsupdatetask.dll,-600)
- Description : $(@%SystemRoot%\system32\mapsupdatetask.dll,-602)
- URI : \Microsoft\Windows\Maps\MapsUpdateTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT40S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-10-21T00:00:00
+ Repetition
- Interval : P1D
- RandomDelay : PT2H
+ Actions
+ ComHandler
- ClassId : {B9033E87-33CF-4D77-BC9B-895AFBBA72E4}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-603)
- URI : \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WER-SystemErrorReporting'] and (EventID=1000 or EventID=1001 or EventID=1006)]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Application Error'] and EventID=1000]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Application Popup'] and EventID=1801]]</Select></Query></QueryList>
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-Kernel-StoreMgr/Operational"><Select Path="Microsoft-Windows-Kernel-StoreMgr/Operational">*[System[Provider[@Name='Microsoft-Windows-Kernel-StoreMgr'] and EventID=6]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Event

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601)
- Author : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600)
- Description : $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-602)
- URI : \Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT2H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : true
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {8168E74A-B39F-46D8-ADCD-7BED477B80A3}
- Data : Time

+ Task
+ RegistrationInfo
- Version : 1.3
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)
- Source : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1901)
- Author : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1902)
- Description : $(@%SystemRoot%\system32\MbaeParserTask.exe,-1903)
- URI : \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT3M
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>
<Query Id='1'>
<Select Path='Microsoft-Windows-DeviceSetupManager/Operational'>*[System/EventID=302] and *[EventData/Data[@Name='Prop_ServiceInfoNamespace']='http://schemas.microsoft.com/windows/2010/12/DeviceMetadata/MobileBroadBandInfo']</Select>
</Query>
</QueryList>
+ Actions
+ Exec
- Command : %SystemRoot%\System32\MbaeParserTask.exe

+ Task
+ RegistrationInfo
- Source : $(@%systemRoot%\System32\lpremove.exe,-100)
- Author : $(@%systemRoot%\System32\lpremove.exe,-100)
- Description : $(@%systemRoot%\System32\lpremove.exe,-101)
- URI : \Microsoft\Windows\MUI\LPRemove
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT9H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P3D
- Deadline : P4D
- Exclusive : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\lpremove.exe

+ Task
+ RegistrationInfo
- Date : 2005-06-23T13:48:00-08:00
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)
- Source : $(@%systemRoot%\System32\PlaySndSrv.Dll,-106)
- Description : $(@%systemRoot%\System32\PlaySndSrv.Dll,-105)
- URI : \Microsoft\Windows\Multimedia\SystemSoundsService
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {2DEA658F-54C1-4227-AF9B-260AB5FC3543}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\nettrace.dll,-6910)
- Author : $(@%SystemRoot%\system32\nettrace.dll,-6911)
- Description : $(@%SystemRoot%\system32\nettrace.dll,-6912)
- URI : \Microsoft\Windows\NetTrace\GatherNetworkInfo
+ Principals
+ Principal
- GroupId : S-1-5-32-545
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\gatherNetworkInfo.vbs
- WorkingDirectory : $(Arg1)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Author : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-500)
- Description : $(@%SystemRoot%\system32\wbem\SDNDiagnosticsProvider.dll,-501)
- URI : \Microsoft\Windows\Network Controller\SDN Diagnostics Task
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2015-08-21T00:00:00
+ Repetition
- Interval : PT30M
+ BootTrigger
+ Actions
+ ComHandler
- ClassId : {C8B67F54-D1CB-44BF-9103-A1AB9A9ED8AD}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5003)
- URI : \Microsoft\Windows\Offline Files\Background Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2008-01-01T00:00:00
+ Repetition
- Interval : PT2H
- RandomDelay : PT20M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}

+ Task
+ RegistrationInfo
- Version : 1.0
- Source : $(@%systemroot%\system32\cscui.dll,-5000)
- Author : $(@%systemroot%\system32\cscui.dll,-5001)
- Description : $(@%systemroot%\system32\cscui.dll,-5002)
- URI : \Microsoft\Windows\Offline Files\Logon Synchronization
+ Principals
+ Principal
- GroupId : S-1-5-11
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : P1D
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT4M
+ Actions
+ ComHandler
- ClassId : {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8}
- Data : Logon

+ Task
+ RegistrationInfo
- Date : 2012-02-07T16:39:20
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-604)
- URI : \Microsoft\Windows\PI\Secure-Boot-Update
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0C9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : SBServicing

+ Task
+ RegistrationInfo
- Date : 2011-07-22T00:00:00.8844064
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-603)
- URI : \Microsoft\Windows\PI\Sqm-Tasks
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : PiSqmTasks

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1301ff;;;S-1-5-80-2661322625-712705077-2999183737-3043590567-590698655)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-102)
- URI : \Microsoft\Windows\PLA\Server Manager Performance Monitor
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 2
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Data
+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
- Author : $(@%SystemRoot%\system32\pnppolicy.dll,-600)
- Description : $(@%SystemRoot%\system32\pnppolicy.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Group Policy
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : P1D
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ Actions
+ ComHandler
- ClassId : {60400283-B242-4FA8-8C25-CAF695B88209}

+ Task
+ RegistrationInfo
- SecurityDescriptor : O:BAG:BAD:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;;FR;;;IU)
- Author : $(@%SystemRoot%\system32\pnpui.dll,-600)
- Description : $(@%SystemRoot%\system32\pnpui.dll,-602)
- URI : \Microsoft\Windows\Plug and Play\Device Install Reboot Required
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 6
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33D009602
+ Actions
+ ComHandler
- ClassId : {48794782-6A1F-47B9-BD52-1D5F95D49C1B}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\pnpclean.dll,-201)
- Author : $(@%SystemRoot%\system32\pnpclean.dll,-201)
- Description : $(@%SystemRoot%\system32\pnpclean.dll,-202)
- URI : \Microsoft\Windows\Plug and Play\Plug and Play Cleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1M
- Deadline : P2M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {DEF03232-9688-11E2-BE7F-B4B52FD966FF}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Author : $(@%SystemRoot%\System32\sppnp.dll,-2000)
- Description : $(@%SystemRoot%\System32\sppnp.dll,-2001)
- URI : \Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %SystemRoot%\System32\drvinst.exe
- Arguments : 6

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%systemRoot%\system32\energytask.dll,-601)
- Author : $(@%systemRoot%\system32\energytask.dll,-600)
- Description : $(@%systemRoot%\system32\energytask.dll,-602)
- URI : \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
- Exclusive : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {927EA2AF-1C54-43D5-825E-0074CE028EEE}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;LS)
- Author : $(@%SystemRoot%\system32\rasmbmgr.dll,-201)
- Description : $(@%SystemRoot%\system32\rasmbmgr.dll,-202)
- URI : \Microsoft\Windows\Ras\MobilityManager
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList>







<Query







Id="0"







Path="Application"







>







<Select Path="Application">*[System[Provider[@Name='RasClient'] and (Level=4 or Level=0) and (EventID=20281)]]</Select>







</Query>







</QueryList>
+ Actions
+ ComHandler
- ClassId : {C463A0FC-794F-4FDF-9201-01938CEACAFA}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU)(A;;FRFX;;;LS)
- Source : $(@%SystemRoot%\system32\ReAgentTask.dll,-602)
- Author : $(@%SystemRoot%\system32\ReAgentTask.dll,-601)
- Description : $(@%SystemRoot%\system32\ReAgentTask.dll,-603)
- URI : \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
+ Principals
+ Principal
- GroupId : S-1-5-32-544
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT1H
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P14D
- Deadline : P1M
+ Triggers
+ Actions
+ ComHandler
- ClassId : {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047}
- Data : VerifyWinRE

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)(A;;FRFX;;;LS)
- Source : $(@%systemroot%\system32\regidle.dll,-601)
- Author : $(@%systemroot%\system32\regidle.dll,-600)
- Description : $(@%systemroot%\system32\regidle.dll,-602)
- URI : \Microsoft\Windows\Registry\RegIdleBackup
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- Priority : 5
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P10D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {CA767AA8-9157-4604-B64B-40747123D5F2}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:SYD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;AU)(A;;FRFX;;;LU)
- Source : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-101)
- Author : $(@%systemroot%\system32\wbem\mgmtprovider.dll,-102)
- URI : \Microsoft\Windows\Server Manager\CleanupOldPerfLogs
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\cscript.exe
- Arguments : /B /nologo %systemroot%\system32\calluxxprovider.vbs $(Arg0) $(Arg1) $(Arg2)

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%SystemRoot%\system32\svrmgrnc.dll,-101)
- Author : $(@%SystemRoot%\system32\svrmgrnc.dll,-103)
- Description : $(@%SystemRoot%\system32\svrmgrnc.dll,-104)
- URI : \Microsoft\Windows\Server Manager\ServerManager
+ Principals
+ Principal
- GroupId : S-1-5-32-544
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- Priority : 4
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\system32\ServerManagerLauncher.exe

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\Servicing\StartComponentCleanup
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {752073A1-23F2-4396-85F0-8FDB879ED0ED}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\BackgroundUploadTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT3H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {59B9640B-3F70-4D1C-B159-F26EEB8A4C87}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\BackupTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Parallel
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- WaitTimeout : PT3H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {60A4C78C-E2B8-4E6E-876F-DA203B02C05E}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FRFX;;;AU)(A;;FA;;;BA)(A;;FA;;;SY)
- URI : \Microsoft\Windows\SettingSync\NetworkStateChangeTask
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Queue
- Priority : 6
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA33E0B8441
- Data : 03
+ WnfStateChangeTrigger
- StateName : 7510BCA33E0B8441
- Data : 03
+ Actions
+ ComHandler
- ClassId : {A4173A49-F373-4475-9A0F-2D615204DC20}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Author : $(@%SystemRoot%\system32\shell32.dll,-14349)
- Description : $(@%SystemRoot%\system32\shell32.dll,-14350)
- URI : \Microsoft\Windows\Shell\CreateObjectTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT30S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {990A9F8F-301F-45F7-8D0E-68C5952DBA43}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;LS)(A;;FR;;;BA)
- Source : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Author : $(@%systemroot%\system32\srchadmin.dll,-1901)
- Description : $(@%systemroot%\system32\srchadmin.dll,-1902)
- URI : \Microsoft\Windows\Shell\IndexerAutomaticMaintenance
+ Principals
+ Principal
- UserId : S-1-5-19
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
- Deadline : P2D
+ Triggers
+ Actions
+ ComHandler
- ClassId : {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Collection
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- ExecutionTimeLimit : PT10M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT1H
- RandomDelay : PT30M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd publish

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- URI : \Microsoft\Windows\Software Inventory Logging\Configuration
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %systemroot%\system32\cmd.exe
- Arguments : /d /c %systemroot%\system32\silcollector.cmd configure

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-2912274048-3994893941-1669128114-1310430903-1263774323)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-201)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2125-12-12T07:17:24+05:30
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : timer

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-4)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-202)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : logon

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-431836887-2321537645-4075769387-3393595759-2187231311)
- Source : $(@%systemroot%\system32\sppc.dll,-200)
- Author : $(@%systemroot%\system32\sppc.dll,-200)
- Description : $(@%systemroot%\system32\sppc.dll,-203)
- URI : \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="Microsoft-Windows-NetworkProfile/Operational"><Select Path="Microsoft-Windows-NetworkProfile/Operational">*[System[EventID=10000]]</Select></Query></QueryList>
+ Actions
+ ComHandler
- ClassId : {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}
- Data : network

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\SpaceAgent.exe,-1)
- Author : $(@%SystemRoot%\system32\SpaceAgent.exe,-2)
- Description : $(@%SystemRoot%\system32\SpaceAgent.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceAgentTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT6H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7508BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\SpaceAgent.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\spaceman.exe,-1)
- Author : $(@%SystemRoot%\system32\spaceman.exe,-2)
- Description : $(@%SystemRoot%\system32\spaceman.exe,-3)
- URI : \Microsoft\Windows\SpacePort\SpaceManagerTask
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
- Delay : PT2M
+ WnfStateChangeTrigger
- StateName : 7510BCA33E1E8702
+ Actions
+ Exec
- Command : %windir%\system32\spaceman.exe
- Arguments : /Work

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;GA;;;NU)
- URI : \Microsoft\Windows\Speech\SpeechModelDownloadTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT10M
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2004-01-01T00:00:00
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %windir%\system32\speech_onecore\common\SpeechModelDownload.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-602)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA32B1D940D
+ Actions
+ ComHandler
- ClassId : {5C9AB547-345D-4175-9AF6-65133463A100}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FR;;;AU)
- Source : $(@%systemroot%\system32\TieringEngineService.exe,-601)
- Author : $(@%systemroot%\system32\TieringEngineService.exe,-600)
- Description : $(@%systemroot%\system32\TieringEngineService.exe,-603)
- URI : \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2013-01-01T01:00:00
+ Repetition
- Interval : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\defrag.exe
- Arguments : -c -h -g -# -m 8 -i 13500

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)
- Source : $(@%systemroot%\system32\wdc.dll,-10042)
- Author : $(@%systemroot%\system32\wdc.dll,-10041)
- Description : $(@%systemroot%\system32\wdc.dll,-10043)
- URI : \Microsoft\Windows\Task Manager\Interactive
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {855FEC53-D2E4-4999-9E87-3414E9CF0FF4}
- Data : $(Arg0)

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;BU)
- Source : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1000)
- Description : $(@%systemRoot%\system32\MsCtfMonitor.dll,-1001)
- URI : \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 5
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1}

+ Task
+ RegistrationInfo
- Source : $(@%SystemRoot%\system32\TimeSyncTask.dll,-601)
- Author : $(@%SystemRoot%\system32\TimeSyncTask.dll,-600)
- Description : $(@%SystemRoot%\system32\TimeSyncTask.dll,-602)
- URI : \Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
+ Principals
+ Principal
- UserId : S-1-5-19
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- Delay : PT1M
- StateName : 7510BCA32F018915
+ Actions
+ ComHandler
- ClassId : {A31AD6C2-FF4C-43D4-8E90-7101023096F9}
- Data : TimeSyncTask

+ Task
+ RegistrationInfo
- Date : 2013-01-10T16:32:04.2837388
- Author : $(@%SystemRoot%\system32\tzsyncres.dll,-101)
- Description : $(@%SystemRoot%\system32\tzsyncres.dll,-102)
- URI : \Microsoft\Windows\Time Zone\SynchronizeTimeZone
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- ExecutionTimeLimit : PT1H
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P7D
- Deadline : P14D
+ Triggers
+ Actions
+ Exec
- Command : %windir%\system32\tzsync.exe

+ Task
+ RegistrationInfo
- Date : 2015-02-16T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-605)
- URI : \Microsoft\Windows\TPM\Tpm-HASCertRetr
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7508BCA3250F9541
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : HASCertRetr

+ Task
+ RegistrationInfo
- Date : 2010-06-10T17:49:20.8844064
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-1469317444-2401623638-2778953283-1691679301-3481717153)
- Source : $(@%SystemRoot%\system32\TpmTasks.dll,-601)
- Author : $(@%SystemRoot%\system32\TpmTasks.dll,-600)
- Description : $(@%SystemRoot%\system32\TpmTasks.dll,-602)
- URI : \Microsoft\Windows\TPM\Tpm-Maintenance
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7518BCA3391E8B41
+ WnfStateChangeTrigger
- StateName : 7508BCA32A1E890D
+ WnfStateChangeTrigger
- StateName : 750CBCA3290B9641
+ WnfStateChangeTrigger
- StateName : 7510BCA3391E8B41
+ Actions
+ ComHandler
- ClassId : {5014B7C8-934E-4262-9816-887FA745A6C4}
- Data : TpmTasks

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Maintenance Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ MaintenanceSettings
- Period : P1D
+ Triggers
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2024-06-07T15:44:31+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : Display

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Policy Install
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2018-02-03T01:11:17+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartInstall

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Reboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT10M
- StartWhenAvailable : true
- WakeToRun : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ TimeTrigger
- StartBoundary : 2024-05-31T17:16:21+05:30
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : RebootDialog

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-107)
- URI : \Microsoft\Windows\UpdateOrchestrator\Refresh Settings
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2000-01-01T03:00:00
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : RefreshSettings

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\Resume On Boot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
+ Triggers
+ BootTrigger
- Delay : PT5M
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : ResumeUpdate

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : $(@%systemRoot%\system32\usocore.dll,-104)
- Author : $(@%systemRoot%\system32\usocore.dll,-103)
- Description : $(@%systemRoot%\system32\usocore.dll,-105)
- URI : \Microsoft\Windows\UpdateOrchestrator\Schedule Scan
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-09T07:25:01+05:30
+ Repetition
- Interval : PT22H
- RandomDelay : PT4H
+ WnfStateChangeTrigger
- Delay : PT2H5M
- StateName : 750CBCA3290B9641
- Data : 01
+ WnfStateChangeTrigger
- Delay : PT5M
- StateName : 7524BCA33E06830D
- Data : 01
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=8202]]</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %systemroot%\system32\usoclient.exe
- Arguments : StartScan

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7510BCA3381D8941
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : Display

+ Task
+ RegistrationInfo
- URI : \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : true
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ WnfStateChangeTrigger
- StateName : 7520BCA3381D8941
- Data : 01
+ Actions
+ Exec
- Command : %systemroot%\system32\MusNotification.exe
- Arguments : ReadyToReboot

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;LS)
- Author : $(@%systemroot%\system32\upnphost.dll,-215)
- Description : $(@%systemroot%\system32\upnphost.dll,-216)
- URI : \Microsoft\Windows\UPnP\UPnPHostConfig
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ Exec
- Command : sc.exe
- Arguments : config upnphost start= auto

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)
- Source : $(@%SystemRoot%\system32\profsvc,-500)
- Author : $(@%SystemRoot%\system32\profsvc,-500)
- Description : $(@%SystemRoot%\system32\profsvc,-501)
- URI : \Microsoft\Windows\User Profile Service\HiveUploadTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : true
- Enabled : false
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT2M
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT2H
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2007-08-28T00:00:00
+ Repetition
- Interval : PT12H
- RandomDelay : PT1H
+ Actions
+ ComHandler
- ClassId : {BA677074-762C-444B-94C8-8C83F93F6605}

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)(A;;FRFX;;;S-1-5-80-2970612574-78537857-698502321-558674196-1451644582)
- Source : $(@%systemroot%\system32\dps.dll,-601)
- Author : $(@%systemroot%\system32\dps.dll,-600)
- Description : $(@%systemroot%\system32\dps.dll,-602)
- URI : \Microsoft\Windows\WDI\ResolutionHost
+ Principals
+ Principal
- GroupId : S-1-5-4
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : Parallel
- Priority : 10
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ Actions
+ ComHandler
- ClassId : {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}

+ Task
+ RegistrationInfo
- Version : 1.5
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD)
- Source : $(@%SystemRoot%\system32\wer.dll,-292)
- Author : $(@%SystemRoot%\system32\wer.dll,-293)
- Description : $(@%SystemRoot%\system32\wer.dll,-294)
- URI : \Microsoft\Windows\Windows Error Reporting\QueueReporting
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Delay : PT3M
+ WnfStateChangeTrigger
- StateName : 7510BCA33A0B9441
- Data : 01
+ TimeTrigger
- StartBoundary : 2015-01-01T05:30:00+05:30
+ Repetition
- Interval : PT4H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %windir%\system32\wermgr.exe
- Arguments : -upload

+ Task
+ RegistrationInfo
- Author : $(@%SystemRoot%\system32\bfe.dll,-2001)
- Description : $(@%SystemRoot%\system32\bfe.dll,-2002)
- URI : \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ EventTrigger
- Subscription : <QueryList><Query Id="0" Path="System"><Select Path="System">*/System/Provider[@Name='Service Control Manager'] and */System/EventID='7040' and */EventData/Data[@Name='param4']='BFE'</Select></Query></QueryList>
+ Actions
+ Exec
- Command : %windir%\system32\rundll32.exe
- Arguments : bfe.dll,BfeOnServiceStartTypeChange

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FWFR;;;BU)
- Source : $(@%SystemRoot%\system32\mscms.dll,-200)
- Author : $(@%SystemRoot%\system32\mscms.dll,-201)
- Description : $(@%SystemRoot%\system32\mscms.dll,-202)
- URI : \Microsoft\Windows\WindowsColorSystem\Calibration Loader
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Queue
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ SessionStateChangeTrigger
- StateChange : ConsoleConnect
+ Actions
+ ComHandler
- ClassId : {B210D694-C8DF-490D-9576-9E20CDBC20BD}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;IU)
- Source : $(@%SystemRoot%\System32\wuautoappupdate.dll,-601)
- Author : $(@%SystemRoot%\System32\wuautoappupdate.dll,-601)
- Description : $(@%SystemRoot%\System32\wuautoappupdate.dll,-603)
- URI : \Microsoft\Windows\WindowsUpdate\Automatic App Update
+ Principals
+ Principal
- GroupId : S-1-5-4
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT4H
- MultipleInstancesPolicy : Parallel
- StartWhenAvailable : true
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : PT4H
- RandomDelay : PT4H
+ LogonTrigger
- Delay : PT5M
+ Actions
+ ComHandler
- ClassId : {A6BA00FE-40E8-477C-B713-C64A14F18ADB}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FA;;;BA)
- Source : Microsoft Corporation.
- Author : Microsoft Corporation.
- Description : This task is used to start the Windows Update service when needed to perform scheduled operations such as scans.
- URI : \Microsoft\Windows\WindowsUpdate\Scheduled Start
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowStartOnDemand : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2026-01-10T08:22:17+05:30
- RandomDelay : PT1M
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : ConsoleDisconnect
+ SessionStateChangeTrigger
- Enabled : false
- StateChange : RemoteDisconnect
+ WnfStateChangeTrigger
- Enabled : false
- StateName : 7508BCA3380C960C
- Data : 01
+ Actions
+ Exec
- Command : C:\Windows\system32\sc.exe
- Arguments : start wuauserv

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FAFRFX;;;SY)(A;;FAFRFX;;;LS)
- Source : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Author : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Description : $(@%SystemRoot%\System32\sihclient.exe,-102)
- URI : \Microsoft\Windows\WindowsUpdate\sih
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ TimeTrigger
- StartBoundary : 2014-01-01T05:30:00+05:30
+ Repetition
- Interval : PT20H
- RandomDelay : PT4H
+ Actions
+ Exec
- Command : %systemroot%\System32\sihclient.exe

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:(A;;FAFRFX;;;SY)(A;;FAFRFX;;;LS)
- Source : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Author : $(@%SystemRoot%\System32\sihclient.exe,-101)
- Description : $(@%SystemRoot%\System32\sihclient.exe,-103)
- URI : \Microsoft\Windows\WindowsUpdate\sihboot
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2M
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
- StartWhenAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- DisallowStartOnRemoteAppSession : true
- UseUnifiedSchedulingEngine : true
+ Triggers
+ BootTrigger
- Enabled : false
+ Actions
+ Exec
- Command : %systemroot%\System32\sihclient.exe
- Arguments : /boot

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;0x001200a9;;;BU)(A;;0x001200a9;;;WD)(A;;0x001200a9;;;LW)
- Author : $(@%systemroot%\system32\wininet.dll,-16000)
- Description : $(@%systemroot%\system32\wininet.dll,-16001)
- URI : \Microsoft\Windows\Wininet\CacheTask
+ Principals
+ Principal
- GroupId : S-1-5-32-545
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT0S
- MultipleInstancesPolicy : Parallel
+ IdleSettings
- StopOnIdleEnd : false
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ ComHandler
- ClassId : {0358B920-0AC7-461F-98F4-58E32CD89148}

+ Task
+ RegistrationInfo
- SecurityDescriptor : D:AI(A;;FA;;;NS)(A;;GA;;;SY)(A;ID;FA;;;BA)(A;ID;GRGX;;;AU)
- Description : $(@%SystemRoot%\system32\dsregcmd.exe,-101)
- URI : \Microsoft\Windows\Workplace Join\Automatic-Device-Join
+ Principals
+ Principal
- UserId : S-1-5-18
- RunLevel : HighestAvailable
+ Settings
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT5M
- MultipleInstancesPolicy : Queue
- RunOnlyIfNetworkAvailable : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
- Delay : PT1M
+ Actions
+ Exec
- Command : %SystemRoot%\System32\dsregcmd.exe

+ Task
+ RegistrationInfo
- Author : Microsoft
- Description : XblGameSave Standby Task
- URI : \Microsoft\XblGameSave\XblGameSaveTask
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ IdleTrigger
+ Actions
+ Exec
- Command : %windir%\System32\XblGameSaveTask.exe
- Arguments : standby

+ Task
+ RegistrationInfo
- Author : Microsoft
- Description : XblGameSave Logon Task
- URI : \Microsoft\XblGameSave\XblGameSaveTaskLogon
+ Principals
+ Principal
- UserId : S-1-5-18
+ Settings
- DisallowStartIfOnBatteries : true
- StopIfGoingOnBatteries : false
- ExecutionTimeLimit : PT2H
- MultipleInstancesPolicy : IgnoreNew
- RunOnlyIfNetworkAvailable : true
- RunOnlyIfIdle : true
+ IdleSettings
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ LogonTrigger
+ Actions
+ Exec
- Command : %windir%\System32\XblGameSaveTask.exe
- Arguments : logon

+ Task
+ RegistrationInfo
- Version : 1.0
- SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FA;;;S-1-5-20)
- Source : $(@%systemroot%\system32\osppc.dll,-200)
- Author : $(@%systemroot%\system32\osppc.dll,-200)
- Description : $(@%systemroot%\system32\osppc.dll,-201)
- URI : \OfficeSoftwareProtectionPlatform\SvcRestartTask
+ Principals
+ Principal
- UserId : S-1-5-20
+ Settings
- AllowHardTerminate : false
- DisallowStartIfOnBatteries : false
- StopIfGoingOnBatteries : false
- Enabled : false
- ExecutionTimeLimit : PT0S
- Hidden : true
- MultipleInstancesPolicy : IgnoreNew
+ RestartOnFailure
- Count : 3
- Interval : PT1M
- StartWhenAvailable : true
+ IdleSettings
- Duration : PT10M
- WaitTimeout : PT1H
- StopOnIdleEnd : true
- RestartOnIdle : false
- UseUnifiedSchedulingEngine : true
+ Triggers
+ CalendarTrigger
- StartBoundary : 2004-01-01T00:00:00
+ ScheduleByDay
- DaysInterval : 1
+ Actions
+ Exec
- Command : %systemroot%\system32\sc.exe
- Arguments : start osppsvc
70626 - Microsoft Windows AutoRuns Services and Drivers
-
Synopsis
Report programs that are set to start automatically on boot as a service or driver.
Description
Report the registry keys that track programs that are set to start on boot as a service.

These programs can start as a system wide service or be loaded as a driver.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services
Drivers :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%systemroot%\system32\browser.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- disabled
- @%systemroot%\system32\browser.dll,-101

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\dcpsvc.dll,-3001
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dcpsvc.dll,-3002

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.170\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.4)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.4)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Server (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\system32\snmptrap.exe,-3
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @%SystemRoot%\system32\snmptrap.exe,-4

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Agent (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS
- disabled
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- Auto Load
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server CEIP service (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlceip.exe" -Service SQLEXPRESS
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\ssdpsrv.dll,-101

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%SystemRoot%\system32\tileobjserver.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Auto Load
- @%SystemRoot%\system32\tileobjserver.dll,-2

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ Apache Tomcat 9.0 Tomcat9
- D:\XTPL\Tomcat\bin\Tomcat9.exe //RS//Tomcat9
- Load on Demand
- Apache Tomcat 9.0.89 Server - https://tomcat.apache.org/

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-102
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\usocore.dll,-101

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Auto Load
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-104
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-103

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\system32\wudfsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wudfsvc.dll,-1001

+ @%systemroot%\system32\XblAuthManager.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblAuthManager.dll,-101

+ @%systemroot%\system32\XblGameSave.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblGameSave.dll,-101

+ @xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver
- \SystemRoot\System32\drivers\xinputhid.sys
- Load on Demand
-


Services :
+ @%SystemRoot%\system32\AJRouter.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\AJRouter.dll,-1

+ @%SystemRoot%\system32\Alg.exe,-112
- %SystemRoot%\System32\alg.exe
- Load on Demand
- @%SystemRoot%\system32\Alg.exe,-113

+ @%windir%\system32\inetsrv\iisres.dll,-30011
- %windir%\system32\svchost.exe -k apphost
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30012

+ @%systemroot%\system32\appidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\appidsvc.dll,-101

+ @%systemroot%\system32\appinfo.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\appinfo.dll,-101

+ @appmgmts.dll,-3250
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @appmgmts.dll,-3251

+ @%SystemRoot%\System32\AppReadiness.dll,-1000
- %SystemRoot%\System32\svchost.exe -k AppReadiness
- Load on Demand
- @%SystemRoot%\System32\AppReadiness.dll,-1001

+ @%systemroot%\system32\AppVClient.exe,-102
- %systemroot%\system32\AppVClient.exe
- disabled
- @%systemroot%\system32\AppVClient.exe,-101

+ @%SystemRoot%\system32\appxdeploymentserver.dll,-1
- %systemroot%\system32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\appxdeploymentserver.dll,-2

+ @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
- Load on Demand
- @%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-2

+ @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\AudioEndpointBuilder.dll,-205

+ @%SystemRoot%\system32\audiosrv.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\audiosrv.dll,-201

+ Kaspersky Endpoint Security Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r
- Auto Load
- Provides computer protection against viruses, other malicious applications, and network attacks.

+ Kaspersky Seamless Update Service (KES.21.15)
- "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"
- Auto Load
- Lets you install and roll back critical and approved updates of application modules.

+ @%SystemRoot%\system32\AxInstSV.dll,-103
- %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
- Load on Demand
- @%SystemRoot%\system32\AxInstSV.dll,-104

+ @%SystemRoot%\system32\bfe.dll,-1001
- %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\bfe.dll,-1002

+ @%SystemRoot%\system32\qmgr.dll,-1000
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\qmgr.dll,-1001

+ @%windir%\system32\bisrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\bisrv.dll,-101

+ @%systemroot%\system32\browser.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- disabled
- @%systemroot%\system32\browser.dll,-101

+ @%SystemRoot%\System32\bthserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\System32\bthserv.dll,-102

+ @%SystemRoot%\system32\cdpsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\cdpsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-11
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-12

+ @%SystemRoot%\system32\ClipSVC.dll,-103
- %SystemRoot%\System32\svchost.exe -k wsappx
- Load on Demand
- @%SystemRoot%\system32\ClipSVC.dll,-104

+ @comres.dll,-947
- %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- Load on Demand
- @comres.dll,-948

+ @%SystemRoot%\system32\coremessaging.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\coremessaging.dll,-2

+ @%SystemRoot%\system32\cryptsvc.dll,-1001
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\system32\cryptsvc.dll,-1002

+ @%systemroot%\system32\cscsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- disabled
- @%systemroot%\system32\cscsvc.dll,-201

+ @combase.dll,-5012
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @combase.dll,-5013

+ @%SystemRoot%\system32\dcpsvc.dll,-3001
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dcpsvc.dll,-3002

+ @%SystemRoot%\system32\defragsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k defragsvc
- Load on Demand
- @%SystemRoot%\system32\defragsvc.dll,-102

+ @%SystemRoot%\system32\das.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\das.dll,-101

+ @%SystemRoot%\system32\umpnpmgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\system32\DevQueryBroker.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\DevQueryBroker.dll,-101

+ @%SystemRoot%\system32\dhcpcore.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\dhcpcore.dll,-101

+ @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000
- %SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
- Load on Demand
- @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1001

+ @%SystemRoot%\system32\diagtrack.dll,-3001
- %SystemRoot%\System32\svchost.exe -k utcsvc
- Auto Load
- @%SystemRoot%\system32\diagtrack.dll,-3002

+ @%systemroot%\system32\Windows.Internal.Management.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\Windows.Internal.Management.dll,-101

+ @%SystemRoot%\system32\dmwappushsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\dmwappushsvc.dll,-201

+ @%SystemRoot%\System32\dnsapi.dll,-101
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\dnsapi.dll,-102

+ @%systemroot%\system32\dot3svc.dll,-1102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\dot3svc.dll,-1103

+ @%systemroot%\system32\dps.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%systemroot%\system32\dps.dll,-501

+ @%SystemRoot%\system32\DeviceSetupManager.dll,-1000
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\DeviceSetupManager.dll,-1001

+ @%SystemRoot%\system32\dssvc.dll,-10003
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\dssvc.dll,-10002

+ @%systemroot%\system32\eapsvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\eapsvc.dll,-2

+ @%SystemRoot%\system32\efssvc.dll,-100
- %SystemRoot%\System32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\efssvc.dll,-101

+ @%SystemRoot%\system32\embeddedmodesvc.dll,-201
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\embeddedmodesvc.dll,-202

+ @EnterpriseAppMgmtSvc.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Load on Demand
- @EnterpriseAppMgmtSvc.dll,-2

+ @%SystemRoot%\system32\wevtsvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\wevtsvc.dll,-201

+ @comres.dll,-2450
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @comres.dll,-2451

+ @%systemroot%\system32\fdPHost.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\fdPHost.dll,-101

+ @%systemroot%\system32\fdrespub.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\fdrespub.dll,-101

+ @%systemroot%\system32\FntCache.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Auto Load
- @%systemroot%\system32\FntCache.dll,-101

+ @%SystemRoot%\system32\PresentationHost.exe,-3309
- %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
- Load on Demand
- @%SystemRoot%\system32\PresentationHost.exe,-3310

+ @%systemroot%\system32\FrameServer.dll,-100
- %SystemRoot%\System32\svchost.exe -k Camera
- Load on Demand
- @%systemroot%\system32\FrameServer.dll,-101

+ Google Chrome Elevation Service (GoogleChromeElevationService)
- "C:\Program Files\Google\Chrome\Application\143.0.7499.170\elevation_service.exe"
- Load on Demand
- Provides encryption services and a secure way for recovering Google Chrome if it gets out of date. If this service is disabled, Google Chrome may lose access to encrypted data, and Google Chrome may not be able recover itself.

+ Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.4)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update-internal
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ Google Updater Service (GoogleUpdaterService144.0.7547.4)
- "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update
- Auto Load
- Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.

+ @gpapi.dll,-112
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @gpapi.dll,-113

+ @%SystemRoot%\System32\hidserv.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\hidserv.dll,-102

+ @%SystemRoot%\system32\hvhostsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\hvhostsvc.dll,-101

+ @%SystemRoot%\System32\tetheringservice.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\tetheringservice.dll,-4098

+ @%SystemRoot%\system32\ikeext.dll,-501
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\ikeext.dll,-502

+ @%SystemRoot%\system32\iphlpsvc.dll,-500
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Auto Load
- @%SystemRoot%\system32\iphlpsvc.dll,-501

+ @keyiso.dll,-100
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @keyiso.dll,-101

+ Kaspersky Security Center Network Agent
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"
- Auto Load
- Network Agent coordinates interaction between the Administration Server and Kaspersky applications installed on devices.

+ @%systemroot%\system32\kpssvc.dll,-100
- %systemroot%\system32\svchost.exe -k KpsSvcGroup
- Load on Demand
- @%systemroot%\system32\kpssvc.dll,-101

+ Kaspersky Security Network proxy server
- "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"
- Load on Demand
- The KSN proxy service retranslates requests to Kaspersky Security Network and caches the responses.

+ @comres.dll,-2946
- %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation
- Load on Demand
- @comres.dll,-2947

+ @%systemroot%\system32\srvsvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k smbsvcs
- Auto Load
- @%systemroot%\system32\srvsvc.dll,-101

+ @%systemroot%\system32\wkssvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%systemroot%\system32\wkssvc.dll,-101

+ @%SystemRoot%\System32\lfsvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\lfsvc.dll,-2

+ @%SystemRoot%\system32\licensemanagersvc.dll,-200
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\licensemanagersvc.dll,-201

+ @%SystemRoot%\system32\lltdres.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\lltdres.dll,-2

+ @%SystemRoot%\system32\lmhsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\lmhsvc.dll,-102

+ @%windir%\system32\lsm.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\lsm.dll,-1002

+ @%SystemRoot%\System32\moshost.dll,-100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\moshost.dll,-101

+ @%SystemRoot%\system32\FirewallAPI.dll,-23090
- %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
- Auto Load
- @%SystemRoot%\system32\FirewallAPI.dll,-23091

+ @comres.dll,-2797
- %SystemRoot%\System32\msdtc.exe
- Auto Load
- @comres.dll,-2798

+ SQL Server Integration Services 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"
- Auto Load
- Provides management support for SSIS package storage and execution.

+ @%SystemRoot%\system32\iscsidsc.dll,-5000
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\iscsidsc.dll,-5001

+ @%SystemRoot%\system32\msimsg.dll,-27
- %systemroot%\system32\msiexec.exe /V
- Load on Demand
- @%SystemRoot%\system32\msimsg.dll,-32

+ MS-MPI Launch Service
- "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"
- Load on Demand
- Service for launching MS-MPI applications

+ SQL Server (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER
- Load on Demand
- Service to launch full-text filter daemon process which will perform document filtering and word breaking for SQL Server full-text search. Disabling this service will make full-text search features of SQL Server unavailable.

+ SQL Server Launchpad (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
- Auto Load
- Service to launch Advanced Analytics Extensions Launchpad process that enables integration with Microsoft R Open using standard T-SQL statements. Disabling this service will make Advanced Analytics features of SQL Server unavailable.

+ SQL Server (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
- Auto Load
- Provides storage, processing and controlled access of data, and rapid transaction processing.

+ SQL Server Analysis Services (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"
- Auto Load
- Supplies online analytical processing (OLAP) and data mining functionality for business intelligence applications.

+ @%SystemRoot%\system32\ncasvc.dll,-3009
- %SystemRoot%\System32\svchost.exe -k NetSvcs
- Load on Demand
- @%SystemRoot%\system32\ncasvc.dll,-3008

+ @%SystemRoot%\system32\ncbservice.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\ncbservice.dll,-501

+ @%SystemRoot%\System32\netlogon.dll,-102
- %systemroot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\System32\netlogon.dll,-103

+ @%SystemRoot%\system32\netman.dll,-109
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\netman.dll,-110

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195
- "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
- disabled
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8194

+ @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197
- %systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
- Auto Load
- @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8196

+ @%SystemRoot%\system32\netprofmsvc.dll,-202
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\netprofmsvc.dll,-203

+ @%SystemRoot%\system32\NetSetupSvc.dll,-3
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\NetSetupSvc.dll,-4

+ @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Auto Load
- @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8198

+ @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201
- %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- Load on Demand
- @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8200

+ @%SystemRoot%\System32\NgcCtnrSvc.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\NgcCtnrSvc.dll,-2

+ @%SystemRoot%\System32\ngcsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ngcsvc.dll,-101

+ @%SystemRoot%\System32\nlasvc.dll,-1
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%SystemRoot%\System32\nlasvc.dll,-2

+ @%SystemRoot%\system32\nsisvc.dll,-200
- %systemroot%\system32\svchost.exe -k LocalService
- Auto Load
- @%SystemRoot%\system32\nsisvc.dll,-201

+ NXLog
- "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
- Auto Load
- This service is responsible for running the NXLog agent. See www.nxlog.co.

+ Office Source Engine
- "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
- Load on Demand
- Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.

+ Office Software Protection Platform
- "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
- Load on Demand
- Office Software Protection Platform Service (unlocalized description)

+ @%SystemRoot%\system32\pcasvc.dll,-1
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\pcasvc.dll,-2

+ @%systemroot%\sysWow64\perfhost.exe,-2
- %SystemRoot%\SysWow64\perfhost.exe
- Load on Demand
- @%systemroot%\SysWow64\perfhost.exe,-1

+ @%SystemRoot%\system32\PhoneserviceRes.dll,-10000
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\PhoneserviceRes.dll,-10001

+ @%systemroot%\system32\pla.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
- Load on Demand
- @%systemroot%\system32\pla.dll,-501

+ @%SystemRoot%\system32\umpnpmgr.dll,-200
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Load on Demand
- @%SystemRoot%\system32\umpnpmgr.dll,-101

+ @%SystemRoot%\System32\polstore.dll,-5010
- %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\polstore.dll,-5011

+ @%SystemRoot%\system32\umpo.dll,-100
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%SystemRoot%\system32\umpo.dll,-101

+ @%systemroot%\system32\profsvc.dll,-300
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\profsvc.dll,-301

+ @%SystemRoot%\system32\qwave.dll,-1
- %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\system32\qwave.dll,-2

+ @%Systemroot%\system32\rasauto.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasauto.dll,-201

+ @%Systemroot%\system32\rasmans.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%Systemroot%\system32\rasmans.dll,-201

+ @%Systemroot%\system32\mprdim.dll,-200
- %SystemRoot%\System32\svchost.exe -k netsvcs
- disabled
- @%Systemroot%\system32\mprdim.dll,-201

+ Remote Registry
- %SystemRoot%\system32\svchost.exe -k localService
- Load on Demand
- @regsvc.dll,-2

+ @%SystemRoot%\system32\RMapi.dll,-1001
- %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\RMapi.dll,-1002

+ @%windir%\system32\RpcEpMap.dll,-1001
- %SystemRoot%\system32\svchost.exe -k RPCSS
- Auto Load
- @%windir%\system32\RpcEpMap.dll,-1002

+ @%systemroot%\system32\Locator.exe,-2
- %SystemRoot%\system32\locator.exe
- Load on Demand
- @%systemroot%\system32\Locator.exe,-3

+ @combase.dll,-5010
- %SystemRoot%\system32\svchost.exe -k rpcss
- Auto Load
- @combase.dll,-5011

+ @gpapi.dll,-114
- %SystemRoot%\system32\RSoPProv.exe
- Load on Demand
- @gpapi.dll,-115

+ @%systemroot%\system32\sacsvr.dll,-500
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\sacsvr.dll,-501

+ @%SystemRoot%\system32\samsrv.dll,-1
- %SystemRoot%\system32\lsass.exe
- Auto Load
- @%SystemRoot%\system32\samsrv.dll,-2

+ @%SystemRoot%\System32\SCardSvr.dll,-1
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- disabled
- @%SystemRoot%\System32\SCardSvr.dll,-5

+ @%SystemRoot%\System32\ScDeviceEnum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\ScDeviceEnum.dll,-101

+ @%SystemRoot%\system32\schedsvc.dll,-100
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\schedsvc.dll,-101

+ @%SystemRoot%\System32\certprop.dll,-13
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\certprop.dll,-14

+ @%SystemRoot%\system32\seclogon.dll,-7001
- %windir%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\seclogon.dll,-7000

+ @%SystemRoot%\system32\Sens.dll,-200
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\Sens.dll,-201

+ @%SystemRoot%\system32\SensorDataService.exe,-101
- %SystemRoot%\System32\SensorDataService.exe
- Load on Demand
- @%SystemRoot%\system32\SensorDataService.exe,-102

+ @%SystemRoot%\System32\sensorservice.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\sensorservice.dll,-1001

+ @%SystemRoot%\System32\sensrsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%SystemRoot%\System32\sensrsvc.dll,-1001

+ @%SystemRoot%\System32\SessEnv.dll,-1026
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\SessEnv.dll,-1027

+ @%SystemRoot%\system32\ipnathlp.dll,-106
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\ipnathlp.dll,-107

+ @%SystemRoot%\System32\shsvcs.dll,-12288
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\shsvcs.dll,-12289

+ @%SystemRoot%\System32\smphost.dll,-102
- %SystemRoot%\System32\svchost.exe -k smphost
- Load on Demand
- @%SystemRoot%\System32\smphost.dll,-101

+ @%SystemRoot%\system32\snmptrap.exe,-3
- %SystemRoot%\System32\snmptrap.exe
- Load on Demand
- @%SystemRoot%\system32\snmptrap.exe,-4

+ @%SystemRoot%\system32\sppsvc.exe,-101
- %SystemRoot%\system32\sppsvc.exe
- Auto Load
- @%SystemRoot%\system32\sppsvc.exe,-100

+ SQL Server Agent (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS
- disabled
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server Browser
- "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
- Auto Load
- Provides SQL Server connection information to client computers.

+ SQL Server Agent (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
- Auto Load
- Executes jobs, monitors SQL Server, fires alerts, and allows automation of some administrative tasks.

+ SQL Server CEIP service (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service
- Auto Load
- CEIP service for Sql server

+ SQL Server CEIP service (SQLEXPRESS)
- "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlceip.exe" -Service SQLEXPRESS
- Auto Load
- CEIP service for Sql server

+ SQL Server VSS Writer
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- Auto Load
- Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.

+ SQL Server Analysis Services CEIP (MSSQLSERVER)
- "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS
- Auto Load
- CEIP service for Sql Server Analysis Services

+ @%systemroot%\system32\ssdpsrv.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\ssdpsrv.dll,-101

+ SQL Server Integration Services CEIP service 15.0
- "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS
- Auto Load
- CEIP service for Sql server Integration Services

+ @%SystemRoot%\system32\sstpsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\sstpsvc.dll,-201

+ @%SystemRoot%\system32\windows.staterepository.dll,-1
- %SystemRoot%\system32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\system32\windows.staterepository.dll,-2

+ @%SystemRoot%\system32\wiaservc.dll,-9
- %SystemRoot%\system32\svchost.exe -k imgsvc
- Load on Demand
- @%SystemRoot%\system32\wiaservc.dll,-10

+ @%SystemRoot%\System32\StorSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\System32\StorSvc.dll,-101

+ @%SystemRoot%\system32\svsvc.dll,-101
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\svsvc.dll,-102

+ @%SystemRoot%\System32\swprv.dll,-103
- %SystemRoot%\System32\svchost.exe -k swprv
- Load on Demand
- @%SystemRoot%\System32\swprv.dll,-102

+ @%SystemRoot%\system32\sysmain.dll,-1000
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\sysmain.dll,-1001

+ @%windir%\system32\SystemEventsBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k DcomLaunch
- Auto Load
- @%windir%\system32\SystemEventsBrokerServer.dll,-1002

+ @%SystemRoot%\system32\TabSvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\TabSvc.dll,-101

+ @%SystemRoot%\system32\tapisrv.dll,-10100
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\tapisrv.dll,-10101

+ @%SystemRoot%\System32\termsrv.dll,-268
- %SystemRoot%\System32\svchost.exe -k termsvcs
- Load on Demand
- @%SystemRoot%\System32\termsrv.dll,-267

+ @%SystemRoot%\System32\themeservice.dll,-8192
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\System32\themeservice.dll,-8193

+ @%SystemRoot%\system32\TieringEngineService.exe,-702
- %SystemRoot%\system32\TieringEngineService.exe
- Load on Demand
- @%SystemRoot%\system32\TieringEngineService.exe,-701

+ @%SystemRoot%\system32\tileobjserver.dll,-1
- %systemroot%\system32\svchost.exe -k appmodel
- Auto Load
- @%SystemRoot%\system32\tileobjserver.dll,-2

+ @%windir%\system32\TimeBrokerServer.dll,-1001
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%windir%\system32\TimeBrokerServer.dll,-1002

+ Apache Tomcat 9.0 Tomcat9
- D:\XTPL\Tomcat\bin\Tomcat9.exe //RS//Tomcat9
- Load on Demand
- Apache Tomcat 9.0.89 Server - https://tomcat.apache.org/

+ @%SystemRoot%\system32\trkwks.dll,-1
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%SystemRoot%\system32\trkwks.dll,-2

+ @%SystemRoot%\servicing\TrustedInstaller.exe,-100
- %SystemRoot%\servicing\TrustedInstaller.exe
- Load on Demand
- @%SystemRoot%\servicing\TrustedInstaller.exe,-101

+ @%SystemRoot%\system32\tzautoupdate.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\tzautoupdate.dll,-201

+ @%systemroot%\system32\ualsvc.dll,-102
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Auto Load
- @%systemroot%\system32\ualsvc.dll,-101

+ @%systemroot%\system32\AgentService.exe,-102
- %systemroot%\system32\AgentService.exe
- disabled
- @%systemroot%\system32\AgentService.exe,-101

+ @%SystemRoot%\system32\umrdp.dll,-1000
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\umrdp.dll,-1001

+ @%systemroot%\system32\upnphost.dll,-213
- %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
- Load on Demand
- @%systemroot%\system32\upnphost.dll,-214

+ @%systemroot%\system32\usermgr.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%systemroot%\system32\usermgr.dll,-101

+ @%systemroot%\system32\usocore.dll,-102
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\usocore.dll,-101

+ @%SystemRoot%\system32\vaultsvc.dll,-1003
- %SystemRoot%\system32\lsass.exe
- Load on Demand
- @%SystemRoot%\system32\vaultsvc.dll,-1004

+ @%SystemRoot%\system32\vds.exe,-100
- %SystemRoot%\System32\vds.exe
- Load on Demand
- @%SystemRoot%\system32\vds.exe,-112

+ @%systemroot%\system32\icsvc.dll,-801
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-802

+ @%systemroot%\system32\icsvc.dll,-101
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-102

+ @%systemroot%\system32\icsvc.dll,-201
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-202

+ @%systemroot%\system32\icsvcext.dll,-601
- %systemroot%\system32\svchost.exe -k ICService
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-602

+ @%systemroot%\system32\icsvc.dll,-301
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-302

+ @%systemroot%\system32\icsvc.dll,-401
- %systemroot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-402

+ @%systemroot%\system32\icsvc.dll,-901
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvc.dll,-902

+ @%systemroot%\system32\icsvcext.dll,-501
- %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\icsvcext.dll,-502

+ @%systemroot%\system32\vssvc.exe,-102
- %systemroot%\system32\vssvc.exe
- Load on Demand
- @%systemroot%\system32\vssvc.exe,-101

+ @%SystemRoot%\system32\w32time.dll,-200
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\w32time.dll,-201

+ @%windir%\system32\inetsrv\iisres.dll,-30014
- %windir%\system32\svchost.exe -k apphost
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30015

+ @%windir%\system32\inetsrv\iisres.dll,-30003
- %windir%\system32\svchost.exe -k iissvcs
- Auto Load
- @%windir%\system32\inetsrv\iisres.dll,-30004

+ @%SystemRoot%\System32\WalletService.dll,-1000
- %SystemRoot%\System32\svchost.exe -k appmodel
- Load on Demand
- @%SystemRoot%\System32\WalletService.dll,-1001

+ @%windir%\system32\inetsrv\iisres.dll,-30001
- %windir%\system32\svchost.exe -k iissvcs
- Load on Demand
- @%windir%\system32\inetsrv\iisres.dll,-30002

+ @%systemroot%\system32\wbiosrvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
- Auto Load
- @%systemroot%\system32\wbiosrvc.dll,-101

+ @%SystemRoot%\System32\wcmsvc.dll,-4097
- %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
- Auto Load
- @%SystemRoot%\System32\wcmsvc.dll,-4098

+ @%systemroot%\system32\wdi.dll,-502
- %SystemRoot%\System32\svchost.exe -k LocalService
- Load on Demand
- @%systemroot%\system32\wdi.dll,-503

+ @%systemroot%\system32\wdi.dll,-500
- %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%systemroot%\system32\wdi.dll,-501

+ @%SystemRoot%\system32\wecsvc.dll,-200
- %SystemRoot%\system32\svchost.exe -k NetworkService
- Load on Demand
- @%SystemRoot%\system32\wecsvc.dll,-201

+ @%systemroot%\system32\wephostsvc.dll,-100
- %systemroot%\system32\svchost.exe -k WepHostSvcGroup
- Load on Demand
- @%systemroot%\system32\wephostsvc.dll,-101

+ @%SystemRoot%\System32\wercplsupport.dll,-101
- %SystemRoot%\System32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\System32\wercplsupport.dll,-100

+ @%SystemRoot%\System32\wersvc.dll,-100
- %SystemRoot%\System32\svchost.exe -k WerSvcGroup
- Load on Demand
- @%SystemRoot%\System32\wersvc.dll,-101

+ @%SystemRoot%\system32\wiarpc.dll,-2
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wiarpc.dll,-1

+ @%SystemRoot%\system32\winhttp.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalService
- Load on Demand
- @%SystemRoot%\system32\winhttp.dll,-101

+ @%Systemroot%\system32\wbem\wmisvc.dll,-205
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%Systemroot%\system32\wbem\wmisvc.dll,-204

+ @%Systemroot%\system32\wsmsvc.dll,-101
- %SystemRoot%\System32\svchost.exe -k NetworkService
- Auto Load
- @%Systemroot%\system32\wsmsvc.dll,-102

+ VNC Server Version 4
- "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
- Auto Load
-

+ @%SystemRoot%\system32\flightsettings.dll,-104
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\flightsettings.dll,-103

+ @%SystemRoot%\system32\wlidsvc.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%SystemRoot%\system32\wlidsvc.dll,-101

+ @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
- %systemroot%\system32\wbem\WmiApSrv.exe
- Load on Demand
- @%Systemroot%\system32\wbem\wmiapsrv.exe,-111

+ @%SystemRoot%\system32\wpdbusenum.dll,-100
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wpdbusenum.dll,-101

+ @%SystemRoot%\system32\wpnservice.dll,-1
- %systemroot%\system32\svchost.exe -k netsvcs
- Auto Load
- @%SystemRoot%\system32\wpnservice.dll,-2

+ @%systemroot%\system32\SearchIndexer.exe,-103
- %systemroot%\system32\SearchIndexer.exe /Embedding
- disabled
- @%systemroot%\system32\SearchIndexer.exe,-104

+ @%systemroot%\system32\wuaueng.dll,-105
- %systemroot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\wuaueng.dll,-106

+ @%SystemRoot%\system32\wudfsvc.dll,-1000
- %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
- Load on Demand
- @%SystemRoot%\system32\wudfsvc.dll,-1001

+ @%systemroot%\system32\XblAuthManager.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblAuthManager.dll,-101

+ @%systemroot%\system32\XblGameSave.dll,-100
- %SystemRoot%\system32\svchost.exe -k netsvcs
- Load on Demand
- @%systemroot%\system32\XblGameSave.dll,-101
70629 - Microsoft Windows AutoRuns Winlogon
-
Synopsis
Report programs that startup associates with the winlogon process.
Description
Report the startup locations associated with the winlogon process.

These values could add features to the logon process, assist in authentication, or set screen savers.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers
+ CLSID : {1b283861-754f-4022-ad47-a5eaaa618894}
- Name : Smartcard Reader Selection Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {1ee7337f-85ac-45e2-a23c-37c753209769}
- Name : Smartcard WinRT Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {2135f72a-90b5-4ed3-a7f1-8bb705ac276a}
- Name : PicturePasswordLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {25CBB996-92ED-457e-B28C-4774084BD562}
- Name : GenericProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {3dd6bec0-8193-4ffe-ae25-e08e39ea4063}
- Name : NPProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {48B4E58D-2791-456C-9091-D524C6C706F2}
- Name : Secondary Authentication Factor Credential Provider
- Value : C:\Windows\System32\devicengccredprov.dll

+ CLSID : {600e7adb-da3e-41a4-9225-3c0399e88c0c}
- Name : CngCredUICredentialProvider
- Value : %systemroot%\system32\cngcredui.dll

+ CLSID : {60b78e88-ead8-445c-9cfd-0b87f74ea6cd}
- Name : PasswordProvider
- Value : %SystemRoot%\system32\credprovs.dll

+ CLSID : {8AF662BF-65A0-4D0A-A540-A338A999D36F}
- Name : FaceCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {8FD7E19C-3BF7-489B-A72C-846AB3678C96}
- Name : Smartcard Credential Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {94596c7e-3744-41ce-893e-bbf09122f76a}
- Name : Smartcard Pin Provider
- Value : %SystemRoot%\system32\SmartcardCredentialProvider.dll

+ CLSID : {A910D941-9DA9-4656-8933-AA1EAE01F76E}
- Name : Remote NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {BEC09223-B018-416D-A0AC-523971B639F5}
- Name : WinBio Credential Provider
- Value : %SystemRoot%\System32\BioCredProv.dll

+ CLSID : {C885AA15-1764-4293-B82A-0586ADD46B35}
- Name : IrisCredentialProvider
- Value : C:\Windows\System32\FaceCredentialProvider.dll

+ CLSID : {cb82ea12-9f71-446d-89e1-8d0924e1256e}
- Name : PINLogonProvider
- Value : %SystemRoot%\system32\credprovslegacy.dll

+ CLSID : {D6886603-9D2F-4EB2-B667-1971041FA96B}
- Name : NGC Credential Provider
- Value : C:\Windows\System32\ngccredprov.dll

+ CLSID : {e74e57b0-6c6d-44d5-9cda-fb2df5ed7435}
- Name : CertCredProvider
- Value : %systemroot%\system32\certCredProvider.dll

+ CLSID : {F8A0B131-5F68-486c-8040-7E8FC3C85BB6}
- Name : WLIDCredentialProvider
- Value : %SystemRoot%\system32\wlidcredprov.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters
+ CLSID : {DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}
- Name : GenericFilter
- Value : %SystemRoot%\system32\credprovs.dll


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers
+ CLSID : {5537E283-B1E7-4EF8-9C6E-7AB0AFE5056D}
- Name : RasProvider
- Value : %SystemRoot%\system32\rasplap.dll




70630 - Microsoft Windows AutoRuns Winsock Provider
-
Synopsis
Report Winsock providers extensions.
Description
A Winsock provider is a type of Layered Service Provider (LSP) that can be used to control protocols by inserting itself into the TCP/IP stack. This can commonly be used to help filter web traffic, enable QoS type services, or anything to hook network traffic controls.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/25, Modified: 2025/12/15
Plugin Output

tcp/0


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
- Name : Hyper-V RAW
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60200
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60201
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\mswsock.dll,-60202
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-100
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-101
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-102
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll

- Name : @%SystemRoot%\System32\wshqos.dll,-103
- PackedCatalogItem : %SystemRoot%\system32\mswsock.dll


+ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
- LibararyPath : %SystemRoot%\system32\napinsp.dll
- LibararyPath : %SystemRoot%\System32\mswsock.dll
- LibararyPath : %SystemRoot%\System32\winrnr.dll
- LibararyPath : %SystemRoot%\system32\NLAapi.dll

92371 - Microsoft Windows DNS Cache
-
Synopsis
Nessus was able to collect and report DNS cache information from the remote host.
Description
Nessus was able to collect details of the DNS cache from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

73.100.17.172.in-addr.arpa
allocation.lkp.net.in
allocation.lkp.net.in

DNS cache information attached.
92363 - Microsoft Windows Device Logs
-
Synopsis
Nessus was able to collect available device logs from the remote host.
Description
Nessus was able to collect available device logs from the remote Windows host and add them as attachments.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Device logs attached.
92364 - Microsoft Windows Environment Variables
-
Synopsis
Nessus was able to collect and report environment variables from the remote host.
Description
Nessus was able to collect system and active account environment variables on the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0757
Plugin Information
Published: 2016/07/19, Modified: 2022/06/24
Plugin Output

tcp/0

Global Environment Variables :
processor_level : 6
comspec : %SystemRoot%\system32\cmd.exe
msmpi_benchmarks : C:\Program Files\Microsoft MPI\Benchmarks\
username : SYSTEM
os : Windows_NT
number_of_processors : 24
java_home : C:\Program Files\Java\jdk-1.8\bin
temp : %SystemRoot%\TEMP
processor_revision : 3e04
path : C:\Program Files\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\Microsoft MPI\Bin\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\130\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\Java\jdk-1.8\bin
tmp : %SystemRoot%\TEMP
processor_identifier : Intel64 Family 6 Model 62 Stepping 4, GenuineIntel
msmpi_bin : C:\Program Files\Microsoft MPI\Bin\
pathext : .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
processor_architecture : AMD64
psmodulepath : %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\Microsoft SQL Server\150\Tools\PowerShell\Modules\;C:\Program Files (x86)\Microsoft SQL Server\130\Tools\PowerShell\Modules\
windir : %SystemRoot%

Active User Environment Variables
- S-1-5-21-3119273522-2427777209-1705870880-500
temp : %USERPROFILE%\AppData\Local\Temp
path : %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;C:\Program Files\Java\jdk-25\bin
tmp : %USERPROFILE%\AppData\Local\Temp
java_home : C:\Program Files\Java\jdk-25
92365 - Microsoft Windows Hosts File
-
Synopsis
Nessus was able to collect the hosts file from the remote host.
Description
Nessus was able to collect the hosts file from the remote Windows host and report it as attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/01/27
Plugin Output

tcp/0

Windows hosts file attached.

MD5: e7ed1af25b1a68ebe03399277cc7bc67
SHA-1: 26853682e740cb5b9c0601d350f8717da6b44f81
SHA-256: 287d1dc38d25f15b60ae4e526bc3ce19f5506b5cd0603a1d5c9f85cc873491d7
187318 - Microsoft Windows Installed
-
Synopsis
The remote host is running Microsoft Windows.
Description
The remote host is running Microsoft Windows.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/12/27, Modified: 2025/12/10
Plugin Output

tcp/0


OS Name : Microsoft Windows Server 2016 1607
Vendor : Microsoft
Product : Windows Server
Release : 2016 1607
Edition : Datacenter
Version : 10.0.14393.2273
Role : server
Kernel : Windows NT 10.0
Architecture : x64
CPE v2.2 : cpe:/o:microsoft:windows_server_2016:10.0.14393.2273:-:~~datacenter~~x64~
CPE v2.3 : cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.2273:-:*:*:datacenter:*:x64:*
Type : local
Method : SMB
Confidence : 100

20811 - Microsoft Windows Installed Software Enumeration (credentialed check)
-
Synopsis
It is possible to enumerate installed software.
Description
This plugin lists software potentially installed on the remote host by crawling the registry entries in :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKLM\SOFTWARE\Microsoft\Updates

Note that these entries do not necessarily mean the applications are actually installed on the remote host - they may have been left behind by uninstallers, or the associated files may have been manually removed.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0501
Plugin Information
Published: 2006/01/26, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following software are installed on the remote host :

Apache Tomcat 9.0 Tomcat9 (remove only) [version 9.0.89]
Google Chrome [version 143.0.7499.170] [installed on 2025/12/25]
Kaspersky Security Center Network Agent [version 14.2.0.26967]
Service Pack 2 for SQL Server 2016 (KB4052908) (64-bit) [version 13.2.5026.0] [installed on 2024/06/06]
Microsoft Help Viewer 2.3 [version 2.3.28307]
Microsoft SQL Server 2016 (64-bit)
Microsoft SQL Server 2019 (64-bit)
Notepad++ (64-bit x64) [version 8.6.6]
Microsoft Office Standard 2010 [version 14.0.6029.1000]
VNC Enterprise Edition E4.6.1 [version E4.6.1] [installed on 2024/05/31]
WinRAR 5.90 (64-bit) [version 5.90.0]
Microsoft SQL Server 2019 Setup (English) [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.14.26429 [version 14.14.26429] [installed on 2024/05/31]
SQL Server 2019 Data quality client [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2016 Database Engine Services [version 13.2.5026.0] [installed on 2024/06/06]
Sql Server Customer Experience Improvement Program [version 13.2.5026.0] [installed on 2024/06/06]
Microsoft ODBC Driver 17 for SQL Server [version 17.10.6.1] [installed on 2024/06/06]
SQL Server 2019 Common Files [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft SQL Server 2016 Setup (English) [version 13.2.5026.0] [installed on 2024/06/06]
SQL Server 2016 Common Files [version 13.2.5026.0] [installed on 2024/06/06]
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [version 10.0.40219] [installed on 2024/06/06]
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 [version 14.14.26429.4]
SQL Server 2019 XEvent [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2019 SQL Diagnostics [version 15.0.2000.5] [installed on 2024/05/31]
Visual Studio 2017 Isolated Shell for SSMS [version 15.0.28307.421] [installed on 2024/06/06]
Microsoft VSS Writer for SQL Server 2019 [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2016 DMF [version 13.0.1601.5] [installed on 2024/06/06]
Microsoft SQL Server 2019 T-SQL Language Service [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2019 Integration Services [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2016 Shared Management Objects [version 13.0.16107.4] [installed on 2024/06/06]
SQL Server 2019 Analysis Services [version 15.0.2000.5] [installed on 2024/05/31]
Java Auto Updater [version 2.8.401.10] [installed on 2024/06/11]
Microsoft SQL Server 2016 T-SQL ScriptDom [version 13.2.5026.0] [installed on 2024/06/06]
SQL Server 2016 Connection Info [version 13.0.16108.4] [installed on 2024/06/06]
Microsoft SQL Server Data-Tier Application Framework (x86) [version 13.0.3225.4] [installed on 2024/06/06]
Microsoft OLE DB Driver for SQL Server [version 18.7.2.0] [installed on 2024/06/06]
Microsoft SQL Server Management Studio - 20.1 [version 20.1.10.0]
Microsoft SQL Server 2019 RsFx Driver [version 15.0.2000.5] [installed on 2024/05/31]
Browser for SQL Server 2019 [version 15.0.2000.5] [installed on 2024/05/31]
Google Update Helper [version 1.3.35.451] [installed on 2024/05/31]
SQL Server 2019 Database Engine Shared [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2019 Shared Management Objects [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft SQL Server 2008 Setup Support Files [version 10.3.5500.0] [installed on 2024/06/06]
Java SE Development Kit 8 Update 401 (64-bit) [version 8.0.4010.10] [installed on 2024/06/11]
SQL Server 2016 Database Engine Shared [version 13.2.5026.0] [installed on 2024/06/06]
SQL Server 2019 Client Tools [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 [version 14.14.26429] [installed on 2024/05/31]
Java 8 Update 401 (64-bit) [version 8.0.4010.10] [installed on 2024/06/11]
Java(TM) SE Development Kit 25.0.1 (64-bit) [version 25.0.1.0] [installed on 2025/12/30]
SQL Server 2016 SQL Diagnostics [version 13.0.1601.5] [installed on 2024/06/06]
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 [version 14.14.26429] [installed on 2024/05/31]
Microsoft SQL Server 2016 RsFx Driver [version 13.2.5026.0] [installed on 2024/06/06]
Microsoft Analysis Services OLE DB Provider [version 16.0.5143.0] [installed on 2024/06/06]
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 [version 14.14.26429.4]
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 [version 12.0.40664] [installed on 2024/06/06]
SQL Server 2019 DMF [version 15.0.2000.5] [installed on 2024/05/31]
Kaspersky Endpoint Security for Windows [version 11.15.8.493]
Kaspersky Endpoint Security for Windows [version 12.3.0.493] [installed on 2025/12/29]
Microsoft MPI (10.0.12498.5) [version 10.0.12498.5] [installed on 2024/05/31]
SQL Server 2016 XEvent [version 13.0.1601.5] [installed on 2024/06/06]
SQL Server 2019 Shared Management Objects Extensions [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support [version 16.0.31110] [installed on 2024/06/06]
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Excel MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office PowerPoint MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Publisher MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Outlook MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Word MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Proof (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Proof (French) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Proof (Spanish) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Office 64-bit Components 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Shared 64-bit MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Proofing (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Shared MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office OneNote MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Shared Setup Metadata MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 [version 14.0.6029.1000] [installed on 2024/08/30]
SSMS Post Install Tasks [version 20.1.10.0] [installed on 2024/06/06]
Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support [version 15.0.27520] [installed on 2024/05/31]
SQL Server 2019 Connection Info [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2019 Data quality service [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft SQL Server 2012 Native Client [version 11.4.7462.6] [installed on 2024/05/31]
SQL Server Management Studio [version 20.1.10.0] [installed on 2024/06/06]
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 [version 12.0.40664.0]
Microsoft ODBC Driver 13 for SQL Server [version 13.2.5026.0] [installed on 2024/06/06]
SQL Server 2019 Database Engine Services [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support [version 15.0.27520] [installed on 2024/05/31]
Microsoft Visual C++ 2017 x64 Additional Runtime - 14.14.26429 [version 14.14.26429] [installed on 2024/05/31]
SQL Server 2016 Shared Management Objects Extensions [version 13.2.5026.0] [installed on 2024/06/06]
SQL Server 2019 Advanced Analytics [version 15.0.2000.5] [installed on 2024/05/31]
NXLog-CE [version 3.2.2329] [installed on 2024/12/12]
SQL Server 2019 Full text search [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 [version 12.0.40664] [installed on 2024/06/06]
SQL Server 2019 Batch Parser [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2016 Batch Parser [version 13.0.1601.5] [installed on 2024/06/06]
SQL Server 2019 SQL Data Quality Common [version 15.0.2000.5] [installed on 2024/05/31]
SQL Server 2019 Client Tools Extensions [version 15.0.2000.5] [installed on 2024/05/31]
Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support [version 16.0.31110] [installed on 2024/06/06]
HP Array Configuration Utility (64-bit) [version 9.10.22.0] [installed on 2025/05/22]
Integration Services [version 16.0.5491.4] [installed on 2024/06/06]
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [version 10.0.40219] [installed on 2024/06/06]
SQL Server Management Studio Language Pack - English [version 20.1.10.0] [installed on 2024/06/06]
Microsoft SQL Server 2016 T-SQL Language Service [version 13.0.14500.10] [installed on 2024/06/06]
Microsoft Visual Studio Tools for Applications 2019 [version 16.0.31110]
Microsoft Visual Studio Tools for Applications 2017 [version 15.0.27520]

The following updates are installed :

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 :
KB2151757 [version 1] [installed on 6/6/2024]
KB2467173 [version 1] [installed on 6/6/2024]
KB2565063 [version 1] [installed on 6/6/2024]
KB982573 [version 1] [installed on 6/6/2024]
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 :
KB2151757 [version 1] [installed on 6/6/2024]
KB2467173 [version 1] [installed on 6/6/2024]
KB2565063 [version 1] [installed on 6/6/2024]
KB982573 [version 1] [installed on 6/6/2024]
178102 - Microsoft Windows Installed Software Version Enumeration
-
Synopsis
Enumerates installed software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2023/07/10, Modified: 2024/07/15
Plugin Output

tcp/445/cifs


The following software information is available on the remote host :

- Microsoft SQL Server Data-Tier Application Framework (x86)
Best Confidence Version : 13.0.3225.4
Version Confidence Level : 2
All Possible Versions : 13.0.3225.4
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218107033
[DisplayName] :
Raw Value : Microsoft SQL Server Data-Tier Application Framework (x86)
[UninstallString] :
Raw Value : MsiExec.exe /X{5084D16B-E1D2-4F25-8B86-A03B4F9E1A72}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.3225.4
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 Connection Info
Best Confidence Version : 13.0.16108.4
Version Confidence Level : 2
All Possible Versions : 13.0.16108.4
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218119916
[DisplayName] :
Raw Value : SQL Server 2016 Connection Info
[UninstallString] :
Raw Value : MsiExec.exe /I{6EE546C8-37CE-47FA-9BED-9EB3CB79E8CA}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.16108.4
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Database Engine Shared
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Shared
[UninstallString] :
Raw Value : MsiExec.exe /I{DE5B7937-D5B5-4157-BC30-BB87F021CFF0}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Help Viewer 2.3
Best Confidence Version : 2.3.28307
Version Confidence Level : 2
All Possible Versions : 51.119.37703, 2.3.28307
Other Version Data
[InstallDate] :
Raw Value : 2024/06/06
[DisplayIcon] :
Raw Value : msiexec.exe
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Help Viewer\v2.3\
[UninstallString] :
Raw Value : MsiExec.exe /X{99DC6816-30B2-32EB-9E12-AF8944C4FA4E}
[VersionMinor] :
Raw Value : 3
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 33779347
Parsed Version : 51.119.37703
[DisplayVersion] :
Raw Value : 2.3.28307
[DisplayName] :
Raw Value : Microsoft Help Viewer 2.3

- Service Pack 2 for SQL Server 2016 (KB4052908) (64-bit)
Best Confidence Version : 2015.131.5026.0
Version Confidence Level : 3
All Possible Versions : 2015.131.5026.0, 13.2.5026.0
Other Version Data
[DisplayName] :
Raw Value : Service Pack 2 for SQL Server 2016 (KB4052908) (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\Update Cache\KB4052908\ServicePack\setup.exe" /Action=RemovePatch /AllInstances
Parsed File Path : C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\Update Cache\KB4052908\ServicePack\setup.exe
Parsed File Version : 2015.131.5026.0
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation

- Browser for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Browser for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /X{5E366957-8D78-4BB5-A790-96F97A9766BD}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Full text search
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Full text search
[UninstallString] :
Raw Value : MsiExec.exe /I{BFF9440C-BC5B-4326-A861-916CC3788A4A}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 XEvent
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 XEvent
[UninstallString] :
Raw Value : MsiExec.exe /I{228C3DC2-695E-4FC7-87E4-6A9CE905DA9B}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- WinRAR 5.90 (64-bit)
Best Confidence Version : 5.90.0.0
Version Confidence Level : 3
All Possible Versions : 5.90.0.0, 5.90.0
Other Version Data
[VersionMajor] :
Raw Value : 5
[InstallLocation] :
Raw Value : C:\Program Files\WinRAR\
[DisplayName] :
Raw Value : WinRAR 5.90 (64-bit)
[UninstallString] :
Raw Value : C:\Program Files\WinRAR\uninstall.exe
Parsed File Path : C:\Program Files\WinRAR\uninstall.exe
Parsed File Version : 5.90.0.0
[DisplayVersion] :
Raw Value : 5.90.0
[Publisher] :
Raw Value : win.rar GmbH
[VersionMinor] :
Raw Value : 90
[DisplayIcon] :
Raw Value : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Path : C:\Program Files\WinRAR\WinRAR.exe
Parsed File Version : 5.90.0.0

- SQL Server 2016 Shared Management Objects Extensions
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : SQL Server 2016 Shared Management Objects Extensions
[UninstallString] :
Raw Value : MsiExec.exe /I{B6E1A5EB-1C58-4A04-B76B-E5FE1BE22CA1}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support
Best Confidence Version : 16.0.31110
Version Confidence Level : 2
All Possible Versions : 16.0.31110
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268466566
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{8E7A3713-551D-333A-9271-10EF4D77A80F}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 16.0.31110
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[InstallDate] :
Raw Value : 2024/08/30
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-0116-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 234887053
[VersionMajor] :
Raw Value : 14
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[DisplayName] :
Raw Value : Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

- SQL Server 2019 Shared Management Objects Extensions
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects Extensions
[UninstallString] :
Raw Value : MsiExec.exe /I{8DDAEBCA-4267-4E16-9FE0-D87F21D36891}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Proof (Spanish) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Proof (Spanish) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft ODBC Driver 17 for SQL Server
Best Confidence Version : 17.10.6.1
Version Confidence Level : 2
All Possible Versions : 17.10.6.1
Other Version Data
[VersionMajor] :
Raw Value : 17
[Version] :
Raw Value : 285868038
[DisplayName] :
Raw Value : Microsoft ODBC Driver 17 for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{0E0F96AC-80DE-4400-A40C-429D63293651}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 17.10.6.1
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 10

- Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{03EBF679-E886-38AD-8E70-28658449F7F9}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 14.14.26429
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 14

- SQL Server Management Studio
Best Confidence Version : 20.1.10.0
Version Confidence Level : 2
All Possible Versions : 20.1.10.0
Other Version Data
[VersionMajor] :
Raw Value : 20
[Version] :
Raw Value : 335609866
[DisplayName] :
Raw Value : SQL Server Management Studio
[UninstallString] :
Raw Value : MsiExec.exe /I{9E497A7E-26BE-4BA3-AF58-071D8D700DA7}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 20.1.10.0
[VersionMinor] :
Raw Value : 1

- NXLog-CE
Best Confidence Version : 3.2.2329
Version Confidence Level : 2
All Possible Versions : 80.70.20553, 3.2.2329
Other Version Data
[InstallDate] :
Raw Value : 2024/12/12
[InstallLocation] :
Raw Value : C:\Program Files\nxlog\
[UninstallString] :
Raw Value : MsiExec.exe /X{BE5E656D-853E-4570-AE57-A45967208689}
[VersionMinor] :
Raw Value : 2
[Version] :
Raw Value : 50465049
Parsed Version : 80.70.20553
[VersionMajor] :
Raw Value : 3
[Publisher] :
Raw Value : NXLog Ltd
[DisplayVersion] :
Raw Value : 3.2.2329
[DisplayName] :
Raw Value : NXLog-CE

- Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664
Best Confidence Version : 12.0.40664
Version Confidence Level : 2
All Possible Versions : 12.0.40664
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201367256
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664
[UninstallString] :
Raw Value : MsiExec.exe /X{D401961D-3A20-3AC7-943B-6139D5BD490A}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 12.0.40664
[VersionMinor] :
Raw Value : 0

- Microsoft Office Shared 64-bit MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[InstallDate] :
Raw Value : 2024/08/30
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-002A-0409-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 234887053
[VersionMajor] :
Raw Value : 14
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[DisplayName] :
Raw Value : Microsoft Office Shared 64-bit MUI (English) 2010

- SQL Server 2016 Common Files
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : SQL Server 2016 Common Files
[UninstallString] :
Raw Value : MsiExec.exe /I{57846DA8-8B5D-4466-B850-E8CDFC94046C}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- SQL Server 2016 Shared Management Objects
Best Confidence Version : 13.0.16107.4
Version Confidence Level : 2
All Possible Versions : 13.0.16107.4
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218119915
[DisplayName] :
Raw Value : SQL Server 2016 Shared Management Objects
[UninstallString] :
Raw Value : MsiExec.exe /I{3E2AB7C7-2019-4126-AF5A-F840DE02DA73}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.16107.4
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664
Best Confidence Version : 12.0.40664.0
Version Confidence Level : 3
All Possible Versions : 12.0.40664.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe
Parsed File Version : 12.0.40664.0
[DisplayVersion] :
Raw Value : 12.0.40664.0
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}\vcredist_x86.exe
Parsed File Version : 12.0.40664.0

- Microsoft Analysis Services OLE DB Provider
Best Confidence Version : 16.0.5143.0
Version Confidence Level : 2
All Possible Versions : 16.0.5143.0
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268440599
[DisplayName] :
Raw Value : Microsoft Analysis Services OLE DB Provider
[UninstallString] :
Raw Value : MsiExec.exe /I{8D96B285-698F-42BA-B483-A0A54D75ECD6}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 16.0.5143.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Proof (French) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Proof (French) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 SQL Data Quality Common
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 SQL Data Quality Common
[UninstallString] :
Raw Value : MsiExec.exe /I{DE61B584-A1E5-4AB4-810B-EC2F8C106B00}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Shared Setup Metadata MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Shared Setup Metadata MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-0115-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Notepad++ (64-bit x64)
Best Confidence Version : 8.6.6.0
Version Confidence Level : 3
All Possible Versions : 8.6.6.0, 8.6.6
Other Version Data
[VersionMajor] :
Raw Value : 8
[DisplayName] :
Raw Value : Notepad++ (64-bit x64)
[UninstallString] :
Raw Value : "C:\Program Files\Notepad++\uninstall.exe"
Parsed File Path : C:\Program Files\Notepad++\uninstall.exe
Parsed File Version : 8.6.6.0
[DisplayVersion] :
Raw Value : 8.6.6
[Publisher] :
Raw Value : Notepad++ Team
[VersionMinor] :
Raw Value : 66
[DisplayIcon] :
Raw Value : C:\Program Files\Notepad++\notepad++.exe
Parsed File Path : C:\Program Files\Notepad++\notepad++.exe
Parsed File Version : 8.6.6.0

- Microsoft Office Excel MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Excel MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-0016-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 SQL Diagnostics
Best Confidence Version : 13.0.1601.5
Version Confidence Level : 2
All Possible Versions : 13.0.1601.5
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218105409
[DisplayName] :
Raw Value : SQL Server 2016 SQL Diagnostics
[UninstallString] :
Raw Value : MsiExec.exe /I{766BE25E-D2B5-4E76-BCB0-29B801BADB3F}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.1601.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 DMF
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 DMF
[UninstallString] :
Raw Value : MsiExec.exe /I{FC8DC283-4A85-467F-8D0E-2FE4606DCCA1}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 Database Engine Shared
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : SQL Server 2016 Database Engine Shared
[UninstallString] :
Raw Value : MsiExec.exe /I{686A81C0-C8E4-46F6-952F-B19A28E8C430}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Integration Services
Best Confidence Version : 16.0.5491.4
Version Confidence Level : 2
All Possible Versions : 16.0.5491.4
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268440947
[DisplayName] :
Raw Value : Integration Services
[UninstallString] :
Raw Value : MsiExec.exe /I{EEFC15C5-D87C-4D6C-AE15-F307A77DEC9B}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 16.0.5491.4
[VersionMinor] :
Raw Value : 0

- Kaspersky Security Center Network Agent
Best Confidence Version : 14.2.0.26967
Version Confidence Level : 2
All Possible Versions : 14.2.0.26967
Other Version Data
[InstallDate] :
Raw Value : 2024/05/31
[DisplayIcon] :
Raw Value : C:\Windows\Installer\{BCF4CF24-88AB-45E1-A6E6-40C8278A70C5}\setup2.ico
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\
[UninstallString] :
Raw Value : MsiExec.exe /I{BCF4CF24-88AB-45E1-A6E6-40C8278A70C5} /l*v "C:\Windows\Temp\$klnagent-uninstall.log"
[VersionMinor] :
Raw Value : 2
[Version] :
Raw Value : 235012096
[VersionMajor] :
Raw Value : 14
[DisplayVersion] :
Raw Value : 14.2.0.26967
[DisplayName] :
Raw Value : Kaspersky Security Center Network Agent

- Microsoft Office Proof (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Proof (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 XEvent
Best Confidence Version : 13.0.1601.5
Version Confidence Level : 2
All Possible Versions : 13.0.1601.5
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218105409
[DisplayName] :
Raw Value : SQL Server 2016 XEvent
[UninstallString] :
Raw Value : MsiExec.exe /I{8CF2CA8E-3984-46B9-B493-F844F3774FA1}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.1601.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Sql Server Customer Experience Improvement Program
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : Sql Server Customer Experience Improvement Program
[UninstallString] :
Raw Value : MsiExec.exe /I{0D9BD39A-A870-4FDF-B590-1E9787CF16D9}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429
Best Confidence Version : 14.14.26429.4
Version Confidence Level : 3
All Possible Versions : 14.14.26429.4
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe
Parsed File Version : 14.14.26429.4
[DisplayVersion] :
Raw Value : 14.14.26429.4
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}\VC_redist.x86.exe
Parsed File Version : 14.14.26429.4

- Microsoft Office 2010 Service Pack 1 (SP1)
Best Confidence Version : 14.0.6022.1000
Version Confidence Level : 3
All Possible Versions : 14.0.6022.1000
Other Version Data
[DisplayName] :
Raw Value : Microsoft Office 2010 Service Pack 1 (SP1)
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-0409-0000-0000000FF1CE}" "{4560037C-E356-444A-A015-D21F487D809E}" "1033" "0"
Parsed File Path : C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe
Parsed File Version : 14.0.6022.1000

- HP Array Configuration Utility (64-bit)
Best Confidence Version : 9.10.22.0
Version Confidence Level : 2
All Possible Versions : 9.10.22.0
Other Version Data
[VersionMajor] :
Raw Value : 9
[Version] :
Raw Value : 151650326
[DisplayName] :
Raw Value : HP Array Configuration Utility (64-bit)
[UninstallString] :
Raw Value : MsiExec.exe /X{ECB61D16-BA45-4560-850E-231E95F8C0AC}
[InstallDate] :
Raw Value : 2025/05/22
[DisplayVersion] :
Raw Value : 9.10.22.0
[Publisher] :
Raw Value : Hewlett-Packard Development Company, L.P.
[VersionMinor] :
Raw Value : 10

- Microsoft SQL Server 2019 T-SQL Language Service
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 T-SQL Language Service
[UninstallString] :
Raw Value : MsiExec.exe /I{31D27B41-A051-49D8-907A-62E0F4A2188C}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Connection Info
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Connection Info
[UninstallString] :
Raw Value : MsiExec.exe /I{99B940D5-1A49-4B6C-B26C-6A88B2C061CA}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java SE Development Kit 8 Update 401 (64-bit)
Best Confidence Version : 8.0.4010.10
Version Confidence Level : 2
All Possible Versions : 8.0.4010.10
Other Version Data
[InstallDate] :
Raw Value : 2024/06/11
[InstallLocation] :
Raw Value : C:\Program Files\Java\jdk-1.8\
[UninstallString] :
Raw Value : MsiExec.exe /I{64A3A4F4-B792-11D6-A78A-00B0D0180401}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134221738
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.4010.10
[DisplayName] :
Raw Value : Java SE Development Kit 8 Update 401 (64-bit)

- Visual Studio 2017 Isolated Shell for SSMS
Best Confidence Version : 15.0.28307.421
Version Confidence Level : 2
All Possible Versions : 15.0.28307.421
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251686547
[DisplayName] :
Raw Value : Visual Studio 2017 Isolated Shell for SSMS
[UninstallString] :
Raw Value : MsiExec.exe /I{29BA18D9-00DF-4A08-BBBE-A0211A31D452}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 15.0.28307.421
[VersionMinor] :
Raw Value : 0

- Microsoft MPI (10.0.12498.5)
Best Confidence Version : 10.0.12498.5
Version Confidence Level : 2
All Possible Versions : 10.0.12498.5
Other Version Data
[InstallDate] :
Raw Value : 2024/05/31
[InstallLocation] :
Raw Value : C:\Program Files\Microsoft MPI\
[UninstallString] :
Raw Value : MsiExec.exe /X{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 167784658
[VersionMajor] :
Raw Value : 10
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 10.0.12498.5
[DisplayName] :
Raw Value : Microsoft MPI (10.0.12498.5)

- SQL Server 2019 Analysis Services
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Analysis Services
[UninstallString] :
Raw Value : MsiExec.exe /I{4514E1C7-80B6-4C82-B488-FCF2F96A2A1A}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java(TM) SE Development Kit 25.0.1 (64-bit)
Best Confidence Version : 25.0.1.0
Version Confidence Level : 2
All Possible Versions : 25.0.1.0
Other Version Data
[InstallDate] :
Raw Value : 2025/12/30
[InstallLocation] :
Raw Value : C:\Program Files\Java\jdk-25\
[UninstallString] :
Raw Value : MsiExec.exe /X{72BBCED8-ABF7-5620-B89C-4081C82552AC}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 419430401
[VersionMajor] :
Raw Value : 25
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 25.0.1.0
[DisplayName] :
Raw Value : Java(TM) SE Development Kit 25.0.1 (64-bit)

- Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x86 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{9594C97E-6A20-38B3-81BB-2778C4780BE1}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.27520
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2012 Native Client
Best Confidence Version : 11.4.7462.6
Version Confidence Level : 2
All Possible Versions : 11.4.7462.6
Other Version Data
[VersionMajor] :
Raw Value : 11
[Version] :
Raw Value : 184818982
[DisplayName] :
Raw Value : Microsoft SQL Server 2012 Native Client
[UninstallString] :
Raw Value : MsiExec.exe /I{9D93D367-A2CC-4378-BD63-79EF3FE76C78}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 11.4.7462.6
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 4

- Google Update Helper
Best Confidence Version : 1.3.35.451
Version Confidence Level : 2
All Possible Versions : 22.151.14425, 1.3.35.451
Other Version Data
[VersionMajor] :
Raw Value : 1
[Version] :
Raw Value : 16973859
Parsed Version : 22.151.14425
[DisplayName] :
Raw Value : Google Update Helper
[UninstallString] :
Raw Value : MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 1.3.35.451
[VersionMinor] :
Raw Value : 3

- Microsoft Office Outlook MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Outlook MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-001A-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2016 (64-bit)
Best Confidence Version : 13.0.5026.0
Version Confidence Level : 3
All Possible Versions : 13.0.5026.0
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server 2016 (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\SQLServer2016\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\SQLServer2016\x64\SetupARP.exe
Parsed File Version : 13.0.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayIcon] :
Raw Value : "C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\SQLServer2016\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\SQLServer2016\x64\SetupARP.exe
Parsed File Version : 13.0.5026.0

- Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
Best Confidence Version : 15.0.27520
Version Confidence Level : 2
All Possible Versions : 15.0.27520
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251685760
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017 x64 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{AFFB9D8D-6E58-38A0-A7DD-F6F1F4247B36}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.27520
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Proofing (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Proofing (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-002C-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2016 RsFx Driver
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : Microsoft SQL Server 2016 RsFx Driver
[UninstallString] :
Raw Value : MsiExec.exe /I{78C0059C-F34F-4249-8F7E-D8C0A8609389}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Kaspersky Endpoint Security for Windows
Best Confidence Version : 11.15.8.493
Version Confidence Level : 2
All Possible Versions : 11.15.8.493
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
[DisplayName] :
Raw Value : Kaspersky Endpoint Security for Windows
[DisplayVersion] :
Raw Value : 11.15.8.493

- Microsoft Office Shared MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Shared MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-006E-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 DMF
Best Confidence Version : 13.0.1601.5
Version Confidence Level : 2
All Possible Versions : 13.0.1601.5
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218105409
[DisplayName] :
Raw Value : SQL Server 2016 DMF
[UninstallString] :
Raw Value : MsiExec.exe /I{2FFF0757-4360-42F5-8814-16BB5CF0145F}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.1601.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 Database Engine Services
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : SQL Server 2016 Database Engine Services
[UninstallString] :
Raw Value : MsiExec.exe /I{0C457EC3-E998-4041-B856-908D5A2C1708}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Microsoft VSS Writer for SQL Server 2019
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft VSS Writer for SQL Server 2019
[UninstallString] :
Raw Value : MsiExec.exe /I{2C33F4D4-E9A5-4DE1-ACFE-3A13464E6703}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server Management Studio - 20.1
Best Confidence Version : 20.1.10.0
Version Confidence Level : 3
All Possible Versions : 20.1.10.0
Other Version Data
[VersionMajor] :
Raw Value : 20
[DisplayName] :
Raw Value : Microsoft SQL Server Management Studio - 20.1
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{57c713b7-9c78-4dd1-bb13-3e618f6fb7c8}\SSMS-Setup-ENU.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{57c713b7-9c78-4dd1-bb13-3e618f6fb7c8}\SSMS-Setup-ENU.exe
Parsed File Version : 20.1.10.0
[DisplayVersion] :
Raw Value : 20.1.10.0
[VersionMinor] :
Raw Value : 1
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{57c713b7-9c78-4dd1-bb13-3e618f6fb7c8}\SSMS-Setup-ENU.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{57c713b7-9c78-4dd1-bb13-3e618f6fb7c8}\SSMS-Setup-ENU.exe
Parsed File Version : 20.1.10.0

- Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{6F0267F3-7467-350D-A8C8-33B72E3658D8}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 14.14.26429
[VersionMinor] :
Raw Value : 14

- SQL Server 2019 Database Engine Services
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Database Engine Services
[UninstallString] :
Raw Value : MsiExec.exe /I{E3E84B2C-FCF6-469F-9FE7-5E8934DB69AD}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Best Confidence Version : 10.0.40219
Version Confidence Level : 2
All Possible Versions : 10.0.40219
Other Version Data
[VersionMajor] :
Raw Value : 10
[Version] :
Raw Value : 167812379
[DisplayName] :
Raw Value : Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
[UninstallString] :
Raw Value : MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 10.0.40219
[VersionMinor] :
Raw Value : 0

- Microsoft Visual Studio Tools for Applications 2017
Best Confidence Version : 15.0.27520.0
Version Confidence Level : 3
All Possible Versions : 15.0.27520.0, 15.0.27520
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2017
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0
[DisplayVersion] :
Raw Value : 15.0.27520
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f895a2f1-ae3f-4212-8af1-7fa1f8c212ea}\vsta_setup.exe
Parsed File Version : 15.0.27520.0

- Microsoft Office OneNote MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office OneNote MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-00A1-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft Office Word MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Word MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-001B-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Shared Management Objects
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Shared Management Objects
[UninstallString] :
Raw Value : MsiExec.exe /I{A8581199-F913-443B-B058-8E8BF317E71C}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Data quality client
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Data quality client
[UninstallString] :
Raw Value : MsiExec.exe /I{089D4965-E3F7-4712-98AB-FA612518F81E}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Kaspersky Endpoint Security for Windows
Best Confidence Version : 12.3.0.493
Version Confidence Level : 2
All Possible Versions : 12.3.0.493
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201523200
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\
[DisplayName] :
Raw Value : Kaspersky Endpoint Security for Windows
[UninstallString] :
Raw Value : msiexec.exe /x {8409A30E-CDF7-4800-B389-FB0A8FB6CE2C}
[InstallDate] :
Raw Value : 2025/12/29
[DisplayVersion] :
Raw Value : 12.3.0.493
[VersionMinor] :
Raw Value : 3

- VNC Enterprise Edition E4.6.1
Best Confidence Version : 51.52.0.0
Version Confidence Level : 3
All Possible Versions : 51.52.0.0, E4.6.1, 4.6.1.54321
Other Version Data
[InstallLocation] :
Raw Value : C:\Program Files\RealVNC\VNC4\
[DisplayName] :
Raw Value : VNC Enterprise Edition E4.6.1
[UninstallString] :
Raw Value : "C:\Program Files\RealVNC\VNC4\unins000.exe"
Parsed File Path : C:\Program Files\RealVNC\VNC4\unins000.exe
Parsed File Version : 51.52.0.0
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : E4.6.1
[Publisher] :
Raw Value : RealVNC Ltd
[DisplayIcon] :
Raw Value : C:\Program Files\RealVNC\VNC4\VNCViewer.exe,0
Parsed File Path : C:\Program Files\RealVNC\VNC4\VNCViewer.exe
Parsed File Version : 4.6.1.54321

- Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429
Best Confidence Version : 14.14.26429.4
Version Confidence Level : 3
All Possible Versions : 14.14.26429.4
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{80586c77-db42-44bb-bfc8-7aebbb220c00}\VC_redist.x64.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{80586c77-db42-44bb-bfc8-7aebbb220c00}\VC_redist.x64.exe
Parsed File Version : 14.14.26429.4
[DisplayVersion] :
Raw Value : 14.14.26429.4
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{80586c77-db42-44bb-bfc8-7aebbb220c00}\VC_redist.x64.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{80586c77-db42-44bb-bfc8-7aebbb220c00}\VC_redist.x64.exe
Parsed File Version : 14.14.26429.4

- SQL Server 2019 Client Tools
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Client Tools
[UninstallString] :
Raw Value : MsiExec.exe /I{9F3D48F5-4184-444C-A810-845C6F078721}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Client Tools Extensions
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Client Tools Extensions
[UninstallString] :
Raw Value : MsiExec.exe /I{EA0ADED4-831D-45B3-B612-C7FD0A1E2BAB}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Office Publisher MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office Publisher MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-0019-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2016 T-SQL ScriptDom
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : Microsoft SQL Server 2016 T-SQL ScriptDom
[UninstallString] :
Raw Value : MsiExec.exe /I{4E5A8BEC-BEB0-4E74-8B0D-8C6728697A0A}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Best Confidence Version : 10.0.40219
Version Confidence Level : 2
All Possible Versions : 10.0.40219
Other Version Data
[VersionMajor] :
Raw Value : 10
[Version] :
Raw Value : 167812379
[DisplayName] :
Raw Value : Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
[UninstallString] :
Raw Value : MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 10.0.40219
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Data quality service
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Data quality service
[UninstallString] :
Raw Value : MsiExec.exe /I{D279840C-4BD6-47E1-8A2E-47E69CD8A863}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java 8 Update 401 (64-bit)
Best Confidence Version : 8.0.4010.10
Version Confidence Level : 2
All Possible Versions : 8.0.4010.10
Other Version Data
[InstallDate] :
Raw Value : 2024/06/11
[InstallLocation] :
Raw Value : C:\Program Files\Java\jre-1.8\
[UninstallString] :
Raw Value : MsiExec.exe /I{71024AE4-039E-4CA4-87B4-2F64180401F0}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 134221738
[VersionMajor] :
Raw Value : 8
[Publisher] :
Raw Value : Oracle Corporation
[DisplayVersion] :
Raw Value : 8.0.4010.10
[DisplayName] :
Raw Value : Java 8 Update 401 (64-bit)

- SQL Server Management Studio Language Pack - English
Best Confidence Version : 20.1.10.0
Version Confidence Level : 2
All Possible Versions : 20.1.10.0
Other Version Data
[VersionMajor] :
Raw Value : 20
[Version] :
Raw Value : 335609866
[DisplayName] :
Raw Value : SQL Server Management Studio Language Pack - English
[UninstallString] :
Raw Value : MsiExec.exe /I{F203903C-AAB3-4DA5-8193-864844BE3141}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 20.1.10.0
[VersionMinor] :
Raw Value : 1

- Microsoft SQL Server 2019 Setup (English)
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 Setup (English)
[UninstallString] :
Raw Value : MsiExec.exe /X{02EC8B46-04E8-4227-89FB-CF5174ABE580}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{7753EC39-3039-3629-98BE-447C5D869C09}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 14.14.26429
[VersionMinor] :
Raw Value : 14

- Microsoft SQL Server 2016 T-SQL Language Service
Best Confidence Version : 13.0.14500.10
Version Confidence Level : 2
All Possible Versions : 13.0.14500.10
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218118308
[DisplayName] :
Raw Value : Microsoft SQL Server 2016 T-SQL Language Service
[UninstallString] :
Raw Value : MsiExec.exe /I{FE3BF1DD-677E-4793-9770-C07AECC88882}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.14500.10
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Java Auto Updater
Best Confidence Version : 2.8.401.10
Version Confidence Level : 2
All Possible Versions : 52.7.37153, 2.8.401.10
Other Version Data
[VersionMajor] :
Raw Value : 2
[Version] :
Raw Value : 34079121
Parsed Version : 52.7.37153
[DisplayName] :
Raw Value : Java Auto Updater
[InstallDate] :
Raw Value : 2024/06/11
[DisplayVersion] :
Raw Value : 2.8.401.10
[VersionMinor] :
Raw Value : 8

- Microsoft SQL Server 2016 Setup (English)
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : Microsoft SQL Server 2016 Setup (English)
[UninstallString] :
Raw Value : MsiExec.exe /X{0FDFF68C-E6E6-414E-AB66-B9AA896A5491}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- SSMS Post Install Tasks
Best Confidence Version : 20.1.10.0
Version Confidence Level : 2
All Possible Versions : 20.1.10.0
Other Version Data
[VersionMajor] :
Raw Value : 20
[Version] :
Raw Value : 335609866
[DisplayName] :
Raw Value : SSMS Post Install Tasks
[UninstallString] :
Raw Value : MsiExec.exe /I{91B24704-293D-4030-A838-D70DAA42B265}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 20.1.10.0
[VersionMinor] :
Raw Value : 1

- SQL Server 2019 Integration Services
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Integration Services
[UninstallString] :
Raw Value : MsiExec.exe /I{BEB4DA4D-7186-4FA6-8563-3EA3F007FBC0}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft ODBC Driver 13 for SQL Server
Best Confidence Version : 13.2.5026.0
Version Confidence Level : 2
All Possible Versions : 13.2.5026.0
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218239906
[DisplayName] :
Raw Value : Microsoft ODBC Driver 13 for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{A5B9FE63-24F8-49BF-B657-FEA9342696B0}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.2.5026.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 2

- Google Chrome
Best Confidence Version : 143.0.7499.170
Version Confidence Level : 3
All Possible Versions : 143.0.7499.170
Other Version Data
[InstallDate] :
Raw Value : 2025/12/25
[DisplayIcon] :
Raw Value : C:\Program Files\Google\Chrome\Application\chrome.exe,0
Parsed File Path : C:\Program Files\Google\Chrome\Application\chrome.exe
Parsed File Version : 143.0.7499.170
[InstallLocation] :
Raw Value : C:\Program Files\Google\Chrome\Application
[UninstallString] :
Raw Value : "C:\Program Files\Google\Chrome\Application\143.0.7499.170\Installer\setup.exe" --uninstall --channel=stable --system-level --verbose-logging
Parsed File Path : C:\Program Files\Google\Chrome\Application\143.0.7499.170\Installer\setup.exe
Parsed File Version : 143.0.7499.170
[VersionMinor] :
Raw Value : 170
[Version] :
Raw Value : 143.0.7499.170
[VersionMajor] :
Raw Value : 7499
[DisplayVersion] :
Raw Value : 143.0.7499.170
[DisplayName] :
Raw Value : Google Chrome

- SQL Server 2019 Common Files
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Common Files
[UninstallString] :
Raw Value : MsiExec.exe /I{5E4344C9-8B97-4ED9-8760-57E221C240F4}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft SQL Server 2019 RsFx Driver
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 RsFx Driver
[UninstallString] :
Raw Value : MsiExec.exe /I{5825CDC4-4E99-4CF9-91FE-DB60C0E2F5EA}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664
Best Confidence Version : 12.0.40664
Version Confidence Level : 2
All Possible Versions : 12.0.40664
Other Version Data
[VersionMajor] :
Raw Value : 12
[Version] :
Raw Value : 201367256
[DisplayName] :
Raw Value : Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664
[UninstallString] :
Raw Value : MsiExec.exe /X{8122DAB1-ED4D-3676-BB0A-CA368196543E}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 12.0.40664
[VersionMinor] :
Raw Value : 0

- SQL Server 2016 Batch Parser
Best Confidence Version : 13.0.1601.5
Version Confidence Level : 2
All Possible Versions : 13.0.1601.5
Other Version Data
[VersionMajor] :
Raw Value : 13
[Version] :
Raw Value : 218105409
[DisplayName] :
Raw Value : SQL Server 2016 Batch Parser
[UninstallString] :
Raw Value : MsiExec.exe /I{D7A905DB-9A1E-4670-9488-F979F8A77A58}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 13.0.1601.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Apache Tomcat 9.0 Tomcat9 (remove only)
Best Confidence Version : 9.0.89.0
Version Confidence Level : 3
All Possible Versions : 9.0.89.0, 9.0.89
Other Version Data
[DisplayName] :
Raw Value : Apache Tomcat 9.0 Tomcat9 (remove only)
[UninstallString] :
Raw Value : "D:\XTPL\Tomcat\Uninstall.exe" -ServiceName="Tomcat9"
Parsed File Path : D:\XTPL\Tomcat\Uninstall.exe
Parsed File Version : 9.0.89.0
[DisplayVersion] :
Raw Value : 9.0.89
[Publisher] :
Raw Value : The Apache Software Foundation
[DisplayIcon] :
Raw Value : "D:\XTPL\Tomcat\tomcat.ico"

- Microsoft SQL Server 2008 Setup Support Files
Best Confidence Version : 10.3.5500.0
Version Confidence Level : 2
All Possible Versions : 10.3.5500.0
Other Version Data
[VersionMajor] :
Raw Value : 10
[Version] :
Raw Value : 167974268
[DisplayName] :
Raw Value : Microsoft SQL Server 2008 Setup Support Files
[UninstallString] :
Raw Value : MsiExec.exe /X{6292D514-17A4-403F-98F9-E150F10C043D}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 10.3.5500.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 3

- Microsoft OLE DB Driver for SQL Server
Best Confidence Version : 18.7.2.0
Version Confidence Level : 2
All Possible Versions : 18.7.2.0
Other Version Data
[VersionMajor] :
Raw Value : 18
[Version] :
Raw Value : 302448642
[DisplayName] :
Raw Value : Microsoft OLE DB Driver for SQL Server
[UninstallString] :
Raw Value : MsiExec.exe /I{5331C869-DED5-43C3-945A-8AE2EE347654}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 18.7.2.0
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 7

- Microsoft Office Office 64-bit Components 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[InstallDate] :
Raw Value : 2024/08/30
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-002A-0000-1000-0000000FF1CE}
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 234887053
[VersionMajor] :
Raw Value : 14
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[DisplayName] :
Raw Value : Microsoft Office Office 64-bit Components 2010

- SQL Server 2019 SQL Diagnostics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 SQL Diagnostics
[UninstallString] :
Raw Value : MsiExec.exe /I{28ED6838-D8E5-454C-A813-12C5EB447CAB}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual C++ 2017 x64 Additional Runtime - 14.14.26429
Best Confidence Version : 14.14.26429
Version Confidence Level : 2
All Possible Versions : 14.14.26429
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 235824957
[DisplayName] :
Raw Value : Microsoft Visual C++ 2017 x64 Additional Runtime - 14.14.26429
[UninstallString] :
Raw Value : MsiExec.exe /X{B12F584A-DE7A-3EE3-8EC4-8A64DBC0F2A7}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 14.14.26429
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 14

- Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support
Best Confidence Version : 16.0.31110
Version Confidence Level : 2
All Possible Versions : 16.0.31110
Other Version Data
[VersionMajor] :
Raw Value : 16
[Version] :
Raw Value : 268466566
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support
[UninstallString] :
Raw Value : MsiExec.exe /X{E7A0CD34-1F9B-3496-ADB3-2F180D302F6A}
[InstallDate] :
Raw Value : 2024/06/06
[DisplayVersion] :
Raw Value : 16.0.31110
[VersionMinor] :
Raw Value : 0

- SQL Server 2019 Advanced Analytics
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Advanced Analytics
[UninstallString] :
Raw Value : MsiExec.exe /I{BD408334-78B9-4024-A8B5-53184C2E8CB3}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

- Microsoft Visual Studio Tools for Applications 2019
Best Confidence Version : 16.0.31110.0
Version Confidence Level : 3
All Possible Versions : 16.0.31110.0, 16.0.31110
Other Version Data
[DisplayName] :
Raw Value : Microsoft Visual Studio Tools for Applications 2019
[UninstallString] :
Raw Value : "C:\ProgramData\Package Cache\{f3fbabb4-bcfb-45eb-8fff-9b784fd68c38}\vsta_setup.exe" /uninstall
Parsed File Path : C:\ProgramData\Package Cache\{f3fbabb4-bcfb-45eb-8fff-9b784fd68c38}\vsta_setup.exe
Parsed File Version : 16.0.31110.0
[DisplayVersion] :
Raw Value : 16.0.31110
[DisplayIcon] :
Raw Value : C:\ProgramData\Package Cache\{f3fbabb4-bcfb-45eb-8fff-9b784fd68c38}\vsta_setup.exe,0
Parsed File Path : C:\ProgramData\Package Cache\{f3fbabb4-bcfb-45eb-8fff-9b784fd68c38}\vsta_setup.exe
Parsed File Version : 16.0.31110.0

- Microsoft Office PowerPoint MUI (English) 2010
Best Confidence Version : 14.0.6029.1000
Version Confidence Level : 2
All Possible Versions : 14.0.6029.1000
Other Version Data
[VersionMajor] :
Raw Value : 14
[Version] :
Raw Value : 234887053
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office\
[DisplayName] :
Raw Value : Microsoft Office PowerPoint MUI (English) 2010
[UninstallString] :
Raw Value : MsiExec.exe /X{90140000-0018-0409-0000-0000000FF1CE}
[InstallDate] :
Raw Value : 2024/08/30
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[VersionMinor] :
Raw Value : 0

- Microsoft Office Standard 2010
Best Confidence Version : 14.0.6010.1000
Version Confidence Level : 3
All Possible Versions : 14.0.6010.1000, 14.0.6029.1000
Other Version Data
[InstallDate] :
Raw Value : 2024/08/30
[DisplayIcon] :
Raw Value : C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OSETUP.DLL,1
[InstallLocation] :
Raw Value : C:\Program Files (x86)\Microsoft Office
[UninstallString] :
Raw Value : "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Parsed File Path : C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe
Parsed File Version : 14.0.6010.1000
[VersionMinor] :
Raw Value : 0
[Version] :
Raw Value : 234887053
[VersionMajor] :
Raw Value : 14
[DisplayVersion] :
Raw Value : 14.0.6029.1000
[DisplayName] :
Raw Value : Microsoft Office Standard 2010

- Microsoft SQL Server 2019 (64-bit)
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 3
All Possible Versions : 15.0.2000.5
Other Version Data
[DisplayName] :
Raw Value : Microsoft SQL Server 2019 (64-bit)
[UninstallString] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[DisplayIcon] :
Raw Value : "C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe"
Parsed File Path : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\SetupARP.exe
Parsed File Version : 15.0.2000.5

- SQL Server 2019 Batch Parser
Best Confidence Version : 15.0.2000.5
Version Confidence Level : 2
All Possible Versions : 15.0.2000.5
Other Version Data
[VersionMajor] :
Raw Value : 15
[Version] :
Raw Value : 251660240
[DisplayName] :
Raw Value : SQL Server 2019 Batch Parser
[UninstallString] :
Raw Value : MsiExec.exe /I{D459615B-83B0-408F-8F39-6CC07C277BA6}
[InstallDate] :
Raw Value : 2024/05/31
[DisplayVersion] :
Raw Value : 15.0.2000.5
[Publisher] :
Raw Value : Microsoft Corporation
[VersionMinor] :
Raw Value : 0

92366 - Microsoft Windows Last Boot Time
-
Synopsis
Nessus was able to collect the remote host's last boot time in a human readable format.
Description
Nessus was able to collect and report the remote host's last boot time as an ISO 8601 timestamp.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/07/09
Plugin Output

tcp/0

Last reboot : 2026-01-05T07:00:37+05:30 (20260105070037.493454+330)

161502 - Microsoft Windows Logged On Users
-
Synopsis
Nessus was able to determine the logged on users from the registry
Description
Using the HKU registry, Nessus was able to enumerate the SIDs of logged on users
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/05/25, Modified: 2025/10/01
Plugin Output

tcp/445/cifs

Logged on users :
- S-1-5-21-3119273522-2427777209-1705870880-500
Domain : XHWAKEYESRV
Username : Production
63080 - Microsoft Windows Mounted Devices
-
Synopsis
It is possible to get a list of mounted devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates mounted devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that the mounted drives agree with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/11/28, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Name : \??\volume{958a328d-1f92-11ef-b7ec-40a8f0208437}
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\e:
Data : DMIO:ID:@JW{
Raw data : 444d494f3a49443ac1f11540d6b61b4a9aa79d57897be692

Name : \dosdevices\f:
Data : \??\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00530043005300490023004300640052006f006d002600560065006e005f004d007300660074002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d002300320026003100660034006100640066006600650026003000260030003000300030003000310023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\d:
Data : DMIO:ID:%Y`\FcK*mJ
Raw data : 444d494f3a49443a255960d9e2fd5c46ae634b2ad56d4a9e

Name : \??\volume{0e289162-1f92-11ef-b7eb-806e6f6e6963}
Data : \??\USBSTOR#CdRom&Ven_HP&Prod_Virtual_DVD-ROM&Rev_#7&2015f5d&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Raw data : 5c003f003f005c00550053004200530054004f00520023004300640052006f006d002600560065006e005f00480050002600500072006f0064005f005600690072007400750061006c005f004400560044002d0052004f004d0026005200650076005f0023003700260032003000310035006600350064002600300023007b00350033006600350036003300300064002d0062003600620066002d0031003100640030002d0039003400660032002d003000300061003000630039003100650066006200380062007d00

Name : \dosdevices\c:
Data : P
Raw data : 87981cb70000501f00000000

92372 - Microsoft Windows NetBIOS over TCP/IP Info
-
Synopsis
Nessus was able to collect and report NBT information from the remote host.
Description
Nessus was able to collect details for NetBIOS over TCP/IP from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

NBT information attached.
First 10 lines of all CSVs:
nbtstat_local.csv:
Interface,Name,Suffix,Type,Status,MAC
10.113.99.73,XHWAKEYESRV,<20>,UNIQUE,Registered,40:A8:F0:20:84:36
10.113.99.73,XHWAKEYESRV,<00>,UNIQUE,Registered,40:A8:F0:20:84:36
10.113.99.73,WORKGROUP,<00>,GROUP,Registered,40:A8:F0:20:84:36
172.17.100.73,XHWAKEYESRV,<20>,UNIQUE,Registered,40:A8:F0:20:84:35
172.17.100.73,XHWAKEYESRV,<00>,UNIQUE,Registered,40:A8:F0:20:84:35
172.17.100.73,WORKGROUP,<00>,GROUP,Registered,40:A8:F0:20:84:35
10.20.30.61,XHWAKEYESRV,<20>,UNIQUE,Registered,40:A8:F0:20:84:37
10.20.30.61,XHWAKEYESRV,<00>,UNIQUE,Registered,40:A8:F0:20:84:37
10.20.30.61,WORKGROUP,<00>,GROUP,Registered,40:A8:F0:20:84:37
10.195.58.173,XHWAKEYESRV,<20>,UNIQUE,Registered,40:A8:F0:20:84:34

103871 - Microsoft Windows Network Adapters
-
Synopsis
Identifies the network adapters installed on the remote host.
Description
Using the supplied credentials, this plugin enumerates and reports the installed network adapters on the remote Windows host.
Solution
Make sure that all of the installed network adapters agrees with your organization's acceptable use and security policies.
Risk Factor
None
References
XREF IAVT:0001-T-0758
Plugin Information
Published: 2017/10/17, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Network Adapter Driver Description : Broadcom NetXtreme Gigabit Ethernet
Network Adapter Driver Version : 17.2.1.0

Network Adapter Driver Description : Broadcom NetXtreme Gigabit Ethernet
Network Adapter Driver Version : 17.2.1.0

Network Adapter Driver Description : Broadcom NetXtreme Gigabit Ethernet
Network Adapter Driver Version : 17.2.1.0

Network Adapter Driver Description : Broadcom NetXtreme Gigabit Ethernet
Network Adapter Driver Version : 17.2.1.0
65791 - Microsoft Windows Portable Devices
-
Synopsis
It is possible to get a list of portable devices that may have been connected to the remote system in the past.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates portable devices that have been connected to the remote host in the past.
See Also
Solution
Make sure that use of the portable devices agrees with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Friendly name : One Touch
Device : SWD#WPDBUSENUM#{3271A276-FB97-11EF-B80C-40A8F0208435}#000000000C900000

92367 - Microsoft Windows PowerShell Execution Policy
-
Synopsis
Nessus was able to collect and report the PowerShell execution policy for the remote host.
Description
Nessus was able to collect and report the PowerShell execution policy for the remote Windows host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2020/06/12
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned
HKLM\SOFTWARE\Wow6432Node\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy : RemoteSigned

151440 - Microsoft Windows Print Spooler Service Enabled
-
Synopsis
The Microsoft Windows Print Spooler service on the remote host is enabled.
Description
The Microsoft Windows Print Spooler service (spoolsv.exe) on the remote host is enabled.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/07/07, Modified: 2021/07/07
Plugin Output

tcp/445/cifs

The Microsoft Windows Print Spooler service on the remote host is enabled.

70329 - Microsoft Windows Process Information
-
Synopsis
Use WMI to obtain running process information.
Description
Report details on the running processes on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to confirm that your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process Overview :
SID: Process (PID)
0 : System Idle Process (0)
0 : |- System (4)
0 : |- smss.exe (620)
2 : notepad.exe (10024)
2 : java.exe (16056)
2 : |- conhost.exe (13856)
1 : winlogon.exe (204)
1 : |- LogonUI.exe (1112)
1 : |- dwm.exe (1120)
2 : winlogon.exe (4780)
2 : |- dwm.exe (6932)
0 : csrss.exe (736)
2 : csrss.exe (8164)
0 : wininit.exe (832)
0 : |- services.exe (912)
0 : |- svchost.exe (1052)
2 : |- taskhostw.exe (10704)
2 : |- sihost.exe (8520)
2 : |- taskhostw.exe (8584)
0 : |- svchost.exe (1060)
2 : |- rdpclip.exe (8380)
0 : |- svchost.exe (1180)
0 : |- svchost.exe (1196)
0 : |- svchost.exe (1428)
0 : |- svchost.exe (1452)
0 : |- sppsvc.exe (14544)
0 : |- svchost.exe (1720)
0 : |- svchost.exe (1728)
0 : |- svchost.exe (192)
0 : |- WmiPrvSE.exe (10608)
2 : |- explorer.exe (12488)
2 : |- explorer.exe (13044)
2 : |- notepad.exe (14648)
2 : |- explorer.exe (14504)
2 : |- explorer.exe (17236)
2 : |- notepad.exe (16808)
2 : |- notepad.exe (9332)
0 : |- unsecapp.exe (2420)
2 : |- explorer.exe (4044)
0 : |- WmiPrvSE.exe (7992)
2 : |- RuntimeBroker.exe (8436)
0 : |- WmiPrvSE.exe (8536)
0 : |- WmiPrvSE.exe (8652)
2 : |- ShellExperienceHost.exe (9244)
2 : |- SearchUI.exe (9392)
2 : |- explorer.exe (9856)
2 : |- explorer.exe (9924)
0 : |- svchost.exe (2212)
0 : |- spoolsv.exe (2304)
0 : |- svchost.exe (2376)
0 : |- svchost.exe (2392)
0 : |- dllhost.exe (2416)
0 : |- avp.exe (2480)
2 : |- avpui.exe (8252)
0 : |- svchost.exe (2488)
0 : |- svchost.exe (2596)
0 : |- w3wp.exe (6984)
0 : |- SMSvcHost.exe (2612)
0 : |- sqlwriter.exe (2660)
0 : |- sqlbrowser.exe (2668)
0 : |- winvnc4.exe (2840)
1 : |- winvnc4.exe (3472)
0 : |- svchost.exe (2852)
0 : |- sqlservr.exe (2928)
0 : |- sqlceip.exe (3132)
0 : |- MsDtsSrvr.exe (3148)
0 : |- sqlceip.exe (3516)
0 : |- sqlceip.exe (3548)
0 : |- sqlservr.exe (3588)
0 : |- sqlceip.exe (3812)
0 : |- SMSvcHost.exe (3904)
0 : |- msmdsrv.exe (4352)
0 : |- Launchpad.exe (6240)
0 : |- SQLAGENT.EXE (6248)
0 : |- conhost.exe (6300)
0 : |- fdlauncher.exe (6280)
0 : |- fdhost.exe (6404)
0 : |- conhost.exe (6412)
0 : |- svchost.exe (7264)
0 : |- svchost.exe (764)
0 : |- avpsus.exe (7692)
0 : |- klnagent.exe (7828)
0 : |- vapm.exe (7040)
0 : |- OSPPSVC.EXE (7900)
0 : |- msdtc.exe (7936)
0 : |- nxlog.exe (8084)
2 : |- svchost.exe (8528)
0 : |- lsass.exe (920)
1 : csrss.exe (840)
2 : jusched.exe (8800)
2 : |- jucheck.exe (9200)
2 : explorer.exe (9204)
2 : |- xHawkEyeServer.exe (13868)
2 : |- xHawkEyeServer.exe (15924)
2 : |- Ssms.exe (284)
2 : |- javaw.exe (7352)
2 : |- xHawkEyeClient.exe (8024)

Process_Information_.csv : information about the running process.
70331 - Microsoft Windows Process Module Information
-
Synopsis
Use WMI to obtain running process module information.
Description
Report details on the running processes modules on the machine.

This plugin is informative only and could be used for forensic investigation, malware detection, and to that confirm your system processes conform to your system policies.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/08, Modified: 2025/12/15
Plugin Output

tcp/0

Process_Modules_.csv : lists the loaded modules for each process.

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/80/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/135/epmap


The Win32 process 'svchost.exe' is listening on this port (pid 764).

This process 'svchost.exe' (pid 764) is hosting the following Windows services :
RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001)
RpcSs (@combase.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/138


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/139/smb


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/500


The Win32 process 'svchost.exe' is listening on this port (pid 1052).

This process 'svchost.exe' (pid 1052) is hosting the following Windows services :
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql


The Win32 process 'sqlservr.exe' is listening on this port (pid 2928).

This process 'sqlservr.exe' (pid 2928) is hosting the following Windows services :
MSSQLSERVER (SQL Server (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/1434


The Win32 process 'sqlbrowser.exe' is listening on this port (pid 2668).

This process 'sqlbrowser.exe' (pid 2668) is hosting the following Windows services :
SQLBrowser (SQL Server Browser)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/1900


The Win32 process 'svchost.exe' is listening on this port (pid 7264).

This process 'svchost.exe' (pid 7264) is hosting the following Windows services :
SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/2383


The Win32 process 'msmdsrv.exe' is listening on this port (pid 4352).

This process 'msmdsrv.exe' (pid 4352) is hosting the following Windows services :
MSSQLServerOLAPService (SQL Server Analysis Services (MSSQLSERVER))

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp


The Win32 process 'svchost.exe' is listening on this port (pid 1060).

This process 'svchost.exe' (pid 1060) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/3389


The Win32 process 'svchost.exe' is listening on this port (pid 1060).

This process 'svchost.exe' (pid 1060) is hosting the following Windows services :
TermService (@%SystemRoot%\System32\termsrv.dll,-268)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/4500


The Win32 process 'svchost.exe' is listening on this port (pid 1052).

This process 'svchost.exe' (pid 1052) is hosting the following Windows services :
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5050


The Win32 process 'svchost.exe' is listening on this port (pid 1428).

This process 'svchost.exe' (pid 1428) is hosting the following Windows services :
EventSystem (@comres.dll,-2450)
FontCache (@%systemroot%\system32\FntCache.dll,-100)
LicenseManager (@%SystemRoot%\system32\licensemanagersvc.dll,-200)
netprofm (@%SystemRoot%\system32\netprofmsvc.dll,-202)
nsi (@%SystemRoot%\system32\nsisvc.dll,-200)
RemoteRegistry (Remote Registry)
WinHttpAutoProxySvc (@%SystemRoot%\system32\winhttp.dll,-100)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5053


The Win32 process 'xHawkEyeServer.exe' is listening on this port (pid 13868).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5059


The Win32 process 'xHawkEyeServer.exe' is listening on this port (pid 15924).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5353


The Win32 process 'svchost.exe' is listening on this port (pid 1728).

This process 'svchost.exe' (pid 1728) is hosting the following Windows services :
CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001)
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)
LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100)
NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1)
WinRM (@%Systemroot%\system32\wsmsvc.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr


The Win32 process 'svchost.exe' is listening on this port (pid 1728).

This process 'svchost.exe' (pid 1728) is hosting the following Windows services :
CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001)
Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101)
LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100)
NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1)
WinRM (@%Systemroot%\system32\wsmsvc.dll,-101)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5800/www


The Win32 process 'winvnc4.exe' is listening on this port (pid 3472).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc


The Win32 process 'winvnc4.exe' is listening on this port (pid 3472).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/5985/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15000


The Win32 process 'klnagent.exe' is listening on this port (pid 7828).

This process 'klnagent.exe' (pid 7828) is hosting the following Windows services :
klnagent (Kaspersky Security Center Network Agent)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/15902


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/18901


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/19096


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/25002


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/28446


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/28702


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/28958


The Win32 process 'javaw.exe' is listening on this port (pid 7352).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/47001/www


The Win32 process 'System' is listening on this port (pid 4).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc


The Win32 process 'wininit.exe' is listening on this port (pid 832).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1180).

This process 'svchost.exe' (pid 1180) is hosting the following Windows services :
Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100)
EventLog (@%SystemRoot%\system32\wevtsvc.dll,-200)
lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101)
TimeBrokerSvc (@%windir%\system32\TimeBrokerServer.dll,-1001)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 1052).

This process 'svchost.exe' (pid 1052) is hosting the following Windows services :
CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11)
gpsvc (@gpapi.dll,-112)
IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501)
iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500)
lfsvc (@%SystemRoot%\System32\lfsvc.dll,-1)
ProfSvc (@%systemroot%\system32\profsvc.dll,-300)
Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
SENS (@%SystemRoot%\system32\Sens.dll,-200)
SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026)
ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288)
Themes (@%SystemRoot%\System32\themeservice.dll,-8192)
UserManager (@%systemroot%\system32\usermgr.dll,-100)
Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205)
WpnService (@%SystemRoot%\system32\wpnservice.dll,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc


The Win32 process 'spoolsv.exe' is listening on this port (pid 2304).

This process 'spoolsv.exe' (pid 2304) is hosting the following Windows services :
Spooler (@%systemroot%\system32\spoolsv.exe,-1)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc


The Win32 process 'svchost.exe' is listening on this port (pid 2212).

This process 'svchost.exe' (pid 2212) is hosting the following Windows services :
PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc


The Win32 process 'services.exe' is listening on this port (pid 912).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/49672/dce-rpc


The Win32 process 'lsass.exe' is listening on this port (pid 920).

This process 'lsass.exe' (pid 920) is hosting the following Windows services :
KeyIso (@keyiso.dll,-100)
SamSs (@%SystemRoot%\system32\samsrv.dll,-1)
VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/51422


The Win32 process 'nxlog.exe' is listening on this port (pid 8084).

This process 'nxlog.exe' (pid 8084) is hosting the following Windows services :
nxlog (NXLog)

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/51528/www


The Win32 process 'java.exe' is listening on this port (pid 16056).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

tcp/51529/www


The Win32 process 'java.exe' is listening on this port (pid 16056).

34252 - Microsoft Windows Remote Listeners Enumeration (WMI)
-
Synopsis
It is possible to obtain the names of processes listening on the remote UDP and TCP ports.
Description
This script uses WMI to list the processes running on the remote host and listening on TCP / UDP ports.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/23, Modified: 2025/12/15
Plugin Output

udp/54436


The Win32 process 'svchost.exe' is listening on this port (pid 7264).

This process 'svchost.exe' (pid 7264) is hosting the following Windows services :
SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)

126527 - Microsoft Windows SAM user enumeration
-
Synopsis
Nessus was able to enumerate domain users from the local SAM.
Description
Using the domain security identifier (SID), Nessus was able to enumerate the domain users on the remote Windows system using the Security Accounts Manager.

Note: Unable to obtain SMB SAMR user data during Agent scans.
Rendering User data obtained by plugin 171956
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2019/07/08, Modified: 2025/06/04
Plugin Output

tcp/0

- DefaultAccount (id S-1-5-21-3119273522-2427777209-503, A user account managed by the system.)
- Guest (id S-1-5-21-3119273522-2427777209-501, Built-in account for guest access to the computer/domain, Guest account)
- LKPAdmin (id S-1-5-21-3119273522-2427777209-1005, LKPAdmin, LKP IT)
- Production (id S-1-5-21-3119273522-2427777209-500, Administrator account, Built-in account for administering the computer/domain)
- tidua (id S-1-5-21-3119273522-2427777209-1006, Audit)

17651 - Microsoft Windows SMB : Obtains the Password Policy
-
Synopsis
It is possible to retrieve the remote host's password policy using the supplied credentials.
Description
Using the supplied credentials it was possible to extract the password policy for the remote Windows host. The password policy must conform to the Informational System Policy.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/03/30, Modified: 2015/01/12
Plugin Output

tcp/445/cifs

The following password policy is defined on the remote host:

Minimum password len: 0
Password history len: 0
Maximum password age (d): 42
Password must meet complexity requirements: Enabled
Minimum password age (d): 0
Forced logoff time (s): Not set
Locked account time (s): 1800
Time between failed logon (s): 1800
Number of invalid logon before locked out (s): 0
50859 - Microsoft Windows SMB : WSUS Client Configured
-
Synopsis
The remote Windows host is utilizing a WSUS server.
Description
The remote host is configured to utilize a Windows Server Update Services (WSUS) server.
See Also
Solution
Verify the remote host is configured to utilize the correct WSUS server.
Risk Factor
None
Plugin Information
Published: 2010/12/01, Modified: 2018/11/15
Plugin Output

tcp/445/cifs


This host is configured to get updates from the following WSUS server :

http://localhost:1550

WSUS Environment Options :

ElevateNonAdmins : undefined
TargetGroup : Automatic Windows Update Policy
TargetGroupEnabled : 1

Automatic Update settings :

AUOptions : 2
AutoInstallMinorUpdates : 0
DetectionFrequency : 22
DetectionFrequencyEnabled : 1
NoAutoRebootWithLoggedOnUsers : 1
NoAutoUpdate : 1
RebootRelaunchTimeout : undefined
RebootRelaunchTimeoutEnabled : undefined
RebootWarningTimeout : undefined
RebootWarningTimeoutEnabled : undefined
RescheduleWaitTime : undefined
RescheduleWaitTimeEnabled : 0
ScheduledInstallDay : 0
ScheduledInstallTime : 10
38689 - Microsoft Windows SMB Last Logged On User Disclosure
-
Synopsis
Nessus was able to identify the last logged on user on the remote host.
Description
By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/05/05, Modified: 2019/09/02
Plugin Output

tcp/445/cifs


Last Successful logon : .\LKPAdmin
10394 - Microsoft Windows SMB Log In Possible
-
Synopsis
It was possible to log into the remote host.
Description
The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :

- Guest account
- Supplied credentials
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/07/21
Plugin Output

tcp/445/cifs

- The SMB tests will be done as tidua/******
10859 - Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration
-
Synopsis
It is possible to obtain the host SID for the remote host.
Description
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier).

The host SID can then be used to get the list of local users.
See Also
Solution
You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value.

Refer to the 'See also' section for guidance.
Risk Factor
None
Plugin Information
Published: 2002/02/13, Modified: 2024/01/31
Plugin Output

tcp/445/cifs


The remote host SID value is : S-1-5-21-3119273522-2427777209-1705870880

The value of 'RestrictAnonymous' setting is : 0
10785 - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
-
Synopsis
It was possible to obtain information about the remote operating system.
Description
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output

tcp/445/cifs

The remote Operating System is : Windows Server 2016 Datacenter 14393
The remote native LAN manager is : Windows Server 2016 Datacenter 6.3
The remote SMB Domain Name is : XHWAKEYESRV
48942 - Microsoft Windows SMB Registry : OS Version and Processor Architecture
-
Synopsis
It was possible to determine the processor architecture, build lab strings, and Windows OS version installed on the remote system.
Description
Nessus was able to determine the processor architecture, build lab strings, and the Windows OS version installed on the remote system by connecting to the remote registry with the supplied credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/31, Modified: 2022/02/01
Plugin Output

tcp/445/cifs

Operating system version = 10.14393
Architecture = x64
Build lab extended = 14393.2273.amd64fre.rs1_release_1.180427-1811
11457 - Microsoft Windows SMB Registry : Winlogon Cached Password Weakness
-
Synopsis
User credentials are stored in memory.
Description
The registry key 'HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ Winlogon\CachedLogonsCount' is not 0. Using a value greater than 0 for the CachedLogonsCount key indicates that the remote Windows host locally caches the passwords of the users when they login, in order to continue to allow the users to login in the case of the failure of the primary domain controller (PDC).

Cached logon credentials could be accessed by an attacker and subjected to brute force attacks.
See Also
Solution
Consult Microsoft documentation and best practices.
Risk Factor
None
Plugin Information
Published: 2003/03/24, Modified: 2018/06/05
Plugin Output

tcp/445/cifs


Max cached logons : 10
10400 - Microsoft Windows SMB Registry Remotely Accessible
-
Synopsis
Access the remote Windows Registry.
Description
It was possible to access the remote Windows Registry using the login / password combination used for the Windows local checks (SMB tests).
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2025/12/16
Plugin Output

tcp/445/cifs

44401 - Microsoft Windows SMB Service Config Enumeration
-
Synopsis
It was possible to enumerate configuration parameters of remote services.
Description
Nessus was able to obtain, via the SMB protocol, the launch parameters of each active service on the remote host (executable path, logon type, etc.).
Solution
Ensure that each service is configured properly.
Risk Factor
None
References
XREF IAVT:0001-T-0752
Plugin Information
Published: 2010/02/05, Modified: 2022/05/16
Plugin Output

tcp/445/cifs


The following services are set to start automatically :

AVP.KES.21.15 startup parameters :
Display name : Kaspersky Endpoint Security Service (KES.21.15)
Service name : AVP.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avp.exe" -r

AppHostSvc startup parameters :
Display name : Application Host Helper Service
Service name : AppHostSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost

BFE startup parameters :
Display name : Base Filtering Engine
Service name : BFE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : RpcSs/

BITS startup parameters :
Display name : Background Intelligent Transfer Service
Service name : BITS
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

BrokerInfrastructure startup parameters :
Display name : Background Tasks Infrastructure Service
Service name : BrokerInfrastructure
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

CDPSvc startup parameters :
Display name : Connected Devices Platform Service
Service name : CDPSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

CDPUserSvc_d0c32 startup parameters :
Display name : CDPUserSvc_d0c32
Service name : CDPUserSvc_d0c32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

CoreMessagingRegistrar startup parameters :
Display name : CoreMessaging
Service name : CoreMessagingRegistrar
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : rpcss/

CryptSvc startup parameters :
Display name : Cryptographic Services
Service name : CryptSvc
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService
Dependencies : RpcSs/

DPS startup parameters :
Display name : Diagnostic Policy Service
Service name : DPS
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

DcomLaunch startup parameters :
Display name : DCOM Server Process Launcher
Service name : DcomLaunch
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch

Dhcp startup parameters :
Display name : DHCP Client
Service name : Dhcp
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : NSI/Tdx/Afd/

DiagTrack startup parameters :
Display name : Connected User Experiences and Telemetry
Service name : DiagTrack
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k utcsvc
Dependencies : RpcSs/

Dnscache startup parameters :
Display name : DNS Client
Service name : Dnscache
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService
Dependencies : Tdx/nsi/

EventLog startup parameters :
Display name : Windows Event Log
Service name : EventLog
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

EventSystem startup parameters :
Display name : COM+ Event System
Service name : EventSystem
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService
Dependencies : rpcss/

FontCache startup parameters :
Display name : Windows Font Cache Service
Service name : FontCache
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

GoogleUpdaterInternalService144.0.7547.4 startup parameters :
Display name : Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.4)
Service name : GoogleUpdaterInternalService144.0.7547.4
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update-internal
Dependencies : RPCSS/

GoogleUpdaterService144.0.7547.4 startup parameters :
Display name : Google Updater Service (GoogleUpdaterService144.0.7547.4)
Service name : GoogleUpdaterService144.0.7547.4
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.4\updater.exe" --system --windows-service --service=update
Dependencies : RPCSS/

IKEEXT startup parameters :
Display name : IKE and AuthIP IPsec Keying Modules
Service name : IKEEXT
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : BFE/nsi/

LSM startup parameters :
Display name : Local Session Manager
Service name : LSM
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/DcomLaunch/RpcSs/

LanmanServer startup parameters :
Display name : Server
Service name : LanmanServer
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k smbsvcs
Dependencies : SamSS/Srv2/

LanmanWorkstation startup parameters :
Display name : Workstation
Service name : LanmanWorkstation
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService
Dependencies : Bowser/MRxSmb20/NSI/

MSDTC startup parameters :
Display name : Distributed Transaction Coordinator
Service name : MSDTC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\msdtc.exe
Dependencies : RPCSS/SamSS/

MSSQL$SQLEXPRESS startup parameters :
Display name : SQL Server (SQLEXPRESS)
Service name : MSSQL$SQLEXPRESS
Log on as : NT Service\MSSQL$SQLEXPRESS
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS

MSSQLLaunchpad startup parameters :
Display name : SQL Server Launchpad (MSSQLSERVER)
Service name : MSSQLLaunchpad
Log on as : NT Service\MSSQLLaunchpad
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\launchpad.exe" -launcher RLauncher.dll -launcher Pythonlauncher.dll -launcher commonlauncher.dll -pipename sqlsatellitelaunch -timeout 600000 -logPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\LOG\ExtensibilityLog" -workingDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExtensibilityData" -externalLanguagesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguagesTemp" -externalLanguagesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLanguages" -externalLibrariesTempDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibrariesTemp" -externalLibrariesDir "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\ExternalLibraries" -satelliteDllPath "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlsatellite.dll"
Dependencies : MSSQLServer/

MSSQLSERVER startup parameters :
Display name : SQL Server (MSSQLSERVER)
Service name : MSSQLSERVER
Log on as : NT Service\MSSQLSERVER
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
Dependencies : KEYISO/

MSSQLServerOLAPService startup parameters :
Display name : SQL Server Analysis Services (MSSQLSERVER)
Service name : MSSQLServerOLAPService
Log on as : NT Service\MSSQLServerOLAPService
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Config"

MapsBroker startup parameters :
Display name : Downloaded Maps Manager
Service name : MapsBroker
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService
Dependencies : rpcss/

MpsSvc startup parameters :
Display name : Windows Firewall
Service name : MpsSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Dependencies : mpsdrv/bfe/

MsDtsServer150 startup parameters :
Display name : SQL Server Integration Services 15.0
Service name : MsDtsServer150
Log on as : NT Service\MsDtsServer150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\MsDtsSrvr.exe"

NetPipeActivator startup parameters :
Display name : Net.Pipe Listener Adapter
Service name : NetPipeActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
Dependencies : was/

NetTcpActivator startup parameters :
Display name : Net.Tcp Listener Adapter
Service name : NetTcpActivator
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Dependencies : was/NetTcpPortSharing/

NlaSvc startup parameters :
Display name : Network Location Awareness
Service name : NlaSvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService
Dependencies : NSI/RpcSs/TcpIp/Dhcp/Eventlog/

OneSyncSvc_d0c32 startup parameters :
Display name : Sync Host_d0c32
Service name : OneSyncSvc_d0c32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PcaSvc startup parameters :
Display name : Program Compatibility Assistant Service
Service name : PcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

Power startup parameters :
Display name : Power
Service name : Power
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch

ProfSvc startup parameters :
Display name : User Profile Service
Service name : ProfSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

RpcEptMapper startup parameters :
Display name : RPC Endpoint Mapper
Service name : RpcEptMapper
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k RPCSS

RpcSs startup parameters :
Display name : Remote Procedure Call (RPC)
Service name : RpcSs
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k rpcss
Dependencies : RpcEptMapper/DcomLaunch/

SENS startup parameters :
Display name : System Event Notification Service
Service name : SENS
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : EventSystem/

SQLBrowser startup parameters :
Display name : SQL Server Browser
Service name : SQLBrowser
Log on as : NT AUTHORITY\LOCALSERVICE
Executable path : "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"

SQLSERVERAGENT startup parameters :
Display name : SQL Server Agent (MSSQLSERVER)
Service name : SQLSERVERAGENT
Log on as : NT Service\SQLSERVERAGENT
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER
Dependencies : MSSQLSERVER/

SQLTELEMETRY startup parameters :
Display name : SQL Server CEIP service (MSSQLSERVER)
Service name : SQLTELEMETRY
Log on as : NT Service\SQLTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service

SQLTELEMETRY$SQLEXPRESS startup parameters :
Display name : SQL Server CEIP service (SQLEXPRESS)
Service name : SQLTELEMETRY$SQLEXPRESS
Log on as : NT Service\SQLTELEMETRY$SQLEXPRESS
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\sqlceip.exe" -Service SQLEXPRESS

SQLWriter startup parameters :
Display name : SQL Server VSS Writer
Service name : SQLWriter
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

SSASTELEMETRY startup parameters :
Display name : SQL Server Analysis Services CEIP (MSSQLSERVER)
Service name : SSASTELEMETRY
Log on as : NT Service\SSASTELEMETRY
Executable path : "C:\Program Files\Microsoft SQL Server\MSAS15.MSSQLSERVER\OLAP\Bin\sqlceip.exe" -Service MSSQLSERVER MSAS

SSISTELEMETRY150 startup parameters :
Display name : SQL Server Integration Services CEIP service 15.0
Service name : SSISTELEMETRY150
Log on as : NT Service\SSISTELEMETRY150
Executable path : "C:\Program Files\Microsoft SQL Server\150\DTS\Binn\sqlceip.exe" -Service default MSIS

SamSs startup parameters :
Display name : Security Accounts Manager
Service name : SamSs
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RPCSS/

Schedule startup parameters :
Display name : Task Scheduler
Service name : Schedule
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/SystemEventsBroker/

ShellHWDetection startup parameters :
Display name : Shell Hardware Detection
Service name : ShellHWDetection
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

Spooler startup parameters :
Display name : Print Spooler
Service name : Spooler
Log on as : LocalSystem
Executable path : C:\Windows\System32\spoolsv.exe
Dependencies : RPCSS/http/

SystemEventsBroker startup parameters :
Display name : System Events Broker
Service name : SystemEventsBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch
Dependencies : RpcEptMapper/RpcSs/

Themes startup parameters :
Display name : Themes
Service name : Themes
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs

TrkWks startup parameters :
Display name : Distributed Link Tracking Client
Service name : TrkWks
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

UALSVC startup parameters :
Display name : User Access Logging Service
Service name : UALSVC
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : WinMgmt/

UserManager startup parameters :
Display name : User Manager
Service name : UserManager
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/ProfSvc/

W3SVC startup parameters :
Display name : World Wide Web Publishing Service
Service name : W3SVC
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : WAS/HTTP/

WbioSrvc startup parameters :
Display name : Windows Biometric Service
Service name : WbioSrvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k WbioSvcGroup
Dependencies : RpcSs/WUDFSvc/

Wcmsvc startup parameters :
Display name : Windows Connection Manager
Service name : Wcmsvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

WinRM startup parameters :
Display name : Windows Remote Management (WS-Management)
Service name : WinRM
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService
Dependencies : RPCSS/HTTP/

WinVNC4 startup parameters :
Display name : VNC Server Version 4
Service name : WinVNC4
Log on as : LocalSystem
Executable path : "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service

Winmgmt startup parameters :
Display name : Windows Management Instrumentation
Service name : Winmgmt
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/

WpnService startup parameters :
Display name : Windows Push Notifications System Service
Service name : WpnService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

avpsus.KES.21.15 startup parameters :
Display name : Kaspersky Seamless Update Service (KES.21.15)
Service name : avpsus.KES.21.15
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpsus.exe"

gpsvc startup parameters :
Display name : Group Policy Client
Service name : gpsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RPCSS/Mup/

iphlpsvc startup parameters :
Display name : IP Helper
Service name : iphlpsvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs
Dependencies : RpcSS/Tdx/winmgmt/tcpip/nsi/WinHttpAutoProxySvc/

klnagent startup parameters :
Display name : Kaspersky Security Center Network Agent
Service name : klnagent
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klnagent.exe"

nsi startup parameters :
Display name : Network Store Interface Service
Service name : nsi
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService
Dependencies : rpcss/nsiproxy/

nxlog startup parameters :
Display name : nxlog
Service name : nxlog
Log on as : LocalSystem
Executable path : "C:\Program Files\nxlog\nxlog.exe" -c "C:\Program Files\nxlog\conf\nxlog.conf"
Dependencies : eventlog/

sppsvc startup parameters :
Display name : Software Protection
Service name : sppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\sppsvc.exe
Dependencies : RpcSs/

tiledatamodelsvc startup parameters :
Display name : Tile Data model server
Service name : tiledatamodelsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel
Dependencies : rpcss/staterepository/

The following services must be started manually :

AJRouter startup parameters :
Display name : AllJoyn Router Service
Service name : AJRouter
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted

ALG startup parameters :
Display name : Application Layer Gateway Service
Service name : ALG
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\alg.exe

AppIDSvc startup parameters :
Display name : Application Identity
Service name : AppIDSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/AppID/CryptSvc/

AppMgmt startup parameters :
Display name : Application Management
Service name : AppMgmt
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs

AppReadiness startup parameters :
Display name : App Readiness
Service name : AppReadiness
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k AppReadiness

AppXSvc startup parameters :
Display name : AppX Deployment Service (AppXSVC)
Service name : AppXSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k wsappx
Dependencies : rpcss/staterepository/

Appinfo startup parameters :
Display name : Application Information
Service name : Appinfo
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/ProfSvc/

AudioEndpointBuilder startup parameters :
Display name : Windows Audio Endpoint Builder
Service name : AudioEndpointBuilder
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

Audiosrv startup parameters :
Display name : Windows Audio
Service name : Audiosrv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : AudioEndpointBuilder/RpcSs/

AxInstSV startup parameters :
Display name : ActiveX Installer (AxInstSV)
Service name : AxInstSV
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k AxInstSVGroup
Dependencies : rpcss/

COMSysApp startup parameters :
Display name : COM+ System Application
Service name : COMSysApp
Log on as : LocalSystem
Executable path : C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Dependencies : RpcSs/EventSystem/SENS/

CertPropSvc startup parameters :
Display name : Certificate Propagation
Service name : CertPropSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

ClipSVC startup parameters :
Display name : Client License Service (ClipSVC)
Service name : ClipSVC
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k wsappx
Dependencies : rpcss/

DcpSvc startup parameters :
Display name : DataCollectionPublishingService
Service name : DcpSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs

DevQueryBroker startup parameters :
Display name : DevQuery Background Discovery Broker
Service name : DevQueryBroker
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

DeviceAssociationService startup parameters :
Display name : Device Association Service
Service name : DeviceAssociationService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

DeviceInstall startup parameters :
Display name : Device Install Service
Service name : DeviceInstall
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch

DmEnrollmentSvc startup parameters :
Display name : Device Management Enrollment Service
Service name : DmEnrollmentSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

DsSvc startup parameters :
Display name : Data Sharing Service
Service name : DsSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

DsmSvc startup parameters :
Display name : Device Setup Manager
Service name : DsmSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

EFS startup parameters :
Display name : Encrypting File System (EFS)
Service name : EFS
Log on as : LocalSystem
Executable path : C:\Windows\System32\lsass.exe
Dependencies : RPCSS/

Eaphost startup parameters :
Display name : Extensible Authentication Protocol
Service name : Eaphost
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RPCSS/KeyIso/

EntAppSvc startup parameters :
Display name : Enterprise App Management Service
Service name : EntAppSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel
Dependencies : rpcss/

FDResPub startup parameters :
Display name : Function Discovery Resource Publication
Service name : FDResPub
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : RpcSs/http/

FontCache3.0.0.0 startup parameters :
Display name : Windows Presentation Foundation Font Cache 3.0.0.0
Service name : FontCache3.0.0.0
Log on as : NT Authority\LocalService
Executable path : C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

FrameServer startup parameters :
Display name : Windows Camera Frame Server
Service name : FrameServer
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k Camera
Dependencies : rpcss/

GoogleChromeElevationService startup parameters :
Display name : Google Chrome Elevation Service (GoogleChromeElevationService)
Service name : GoogleChromeElevationService
Log on as : LocalSystem
Executable path : "C:\Program Files\Google\Chrome\Application\143.0.7499.170\elevation_service.exe"
Dependencies : RPCSS/

HvHost startup parameters :
Display name : HV Host Service
Service name : HvHost
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : hvservice/

KPSSVC startup parameters :
Display name : KDC Proxy Server service (KPS)
Service name : KPSSVC
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k KpsSvcGroup
Dependencies : rpcss/http/

KeyIso startup parameters :
Display name : CNG Key Isolation
Service name : KeyIso
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : RpcSs/

KtmRm startup parameters :
Display name : KtmRm for Distributed Transaction Coordinator
Service name : KtmRm
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation
Dependencies : RPCSS/SamSS/

LicenseManager startup parameters :
Display name : Windows License Manager Service
Service name : LicenseManager
Log on as : NT Authority\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService
Dependencies : rpcss/

MSSQLFDLauncher startup parameters :
Display name : SQL Full-text Filter Daemon Launcher (MSSQLSERVER)
Service name : MSSQLFDLauncher
Log on as : NT Service\MSSQLFDLauncher
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL15.MSSQLSERVER

MSiSCSI startup parameters :
Display name : Microsoft iSCSI Initiator Service
Service name : MSiSCSI
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs

MsMpiLaunchSvc startup parameters :
Display name : MS-MPI Launch Service
Service name : MsMpiLaunchSvc
Log on as : LocalSystem
Executable path : "C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe"

NcaSvc startup parameters :
Display name : Network Connectivity Assistant
Service name : NcaSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k NetSvcs
Dependencies : BFE/dnscache/NSI/iphlpsvc/

NcbService startup parameters :
Display name : Network Connection Broker
Service name : NcbService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSS/tcpip/

NetSetupSvc startup parameters :
Display name : Network Setup Service
Service name : NetSetupSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSs/

NetTcpPortSharing startup parameters :
Display name : Net.Tcp Port Sharing Service
Service name : NetTcpPortSharing
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

Netlogon startup parameters :
Display name : Netlogon
Service name : Netlogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : LanmanWorkstation/

Netman startup parameters :
Display name : Network Connections
Service name : Netman
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/nsi/

NgcCtnrSvc startup parameters :
Display name : Microsoft Passport Container
Service name : NgcCtnrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

NgcSvc startup parameters :
Display name : Microsoft Passport
Service name : NgcSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

PerfHost startup parameters :
Display name : Performance Counter DLL Host
Service name : PerfHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\SysWow64\perfhost.exe
Dependencies : RPCSS/

PhoneSvc startup parameters :
Display name : Phone Service
Service name : PhoneSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService
Dependencies : RpcSs/

PimIndexMaintenanceSvc_d0c32 startup parameters :
Display name : Contact Data_d0c32
Service name : PimIndexMaintenanceSvc_d0c32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

PlugPlay startup parameters :
Display name : Plug and Play
Service name : PlugPlay
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k DcomLaunch

PolicyAgent startup parameters :
Display name : IPsec Policy Agent
Service name : PolicyAgent
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
Dependencies : Tcpip/bfe/

PrintNotify startup parameters :
Display name : Printer Extensions and Notifications
Service name : PrintNotify
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k print
Dependencies : RpcSs/

QWAVE startup parameters :
Display name : Quality Windows Audio Video Experience
Service name : QWAVE
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : rpcss/psched/QWAVEdrv/LLTDIO/

RSoPProv startup parameters :
Display name : Resultant Set of Policy Provider
Service name : RSoPProv
Log on as : LocalSystem
Executable path : C:\Windows\system32\RSoPProv.exe
Dependencies : RPCSS/

RasAuto startup parameters :
Display name : Remote Access Auto Connection Manager
Service name : RasAuto
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RasAcd/

RasMan startup parameters :
Display name : Remote Access Connection Manager
Service name : RasMan
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : SstpSvc/

RemoteRegistry startup parameters :
Display name : Remote Registry
Service name : RemoteRegistry
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k localService
Dependencies : RPCSS/

RmSvc startup parameters :
Display name : Radio Management Service
Service name : RmSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/

RpcLocator startup parameters :
Display name : Remote Procedure Call (RPC) Locator
Service name : RpcLocator
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\locator.exe

SCPolicySvc startup parameters :
Display name : Smart Card Removal Policy
Service name : SCPolicySvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

SNMPTRAP startup parameters :
Display name : SNMP Trap
Service name : SNMPTRAP
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\snmptrap.exe

SSDPSRV startup parameters :
Display name : SSDP Discovery
Service name : SSDPSRV
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : HTTP/

ScDeviceEnum startup parameters :
Display name : Smart Card Device Enumeration Service
Service name : ScDeviceEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

SensorDataService startup parameters :
Display name : Sensor Data Service
Service name : SensorDataService
Log on as : LocalSystem
Executable path : C:\Windows\System32\SensorDataService.exe

SensorService startup parameters :
Display name : Sensor Service
Service name : SensorService
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

SensrSvc startup parameters :
Display name : Sensor Monitoring Service
Service name : SensrSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

SessionEnv startup parameters :
Display name : Remote Desktop Configuration
Service name : SessionEnv
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RPCSS/LanmanWorkstation/

SharedAccess startup parameters :
Display name : Internet Connection Sharing (ICS)
Service name : SharedAccess
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : BFE/

SstpSvc startup parameters :
Display name : Secure Socket Tunneling Protocol Service
Service name : SstpSvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

StateRepository startup parameters :
Display name : State Repository Service
Service name : StateRepository
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k appmodel
Dependencies : rpcss/

StorSvc startup parameters :
Display name : Storage Service
Service name : StorSvc
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

SysMain startup parameters :
Display name : Superfetch
Service name : SysMain
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : rpcss/

TabletInputService startup parameters :
Display name : Touch Keyboard and Handwriting Panel Service
Service name : TabletInputService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

TapiSrv startup parameters :
Display name : Telephony
Service name : TapiSrv
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k NetworkService
Dependencies : RpcSs/

TermService startup parameters :
Display name : Remote Desktop Services
Service name : TermService
Log on as : NT Authority\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k termsvcs
Dependencies : RPCSS/

TieringEngineService startup parameters :
Display name : Storage Tiers Management
Service name : TieringEngineService
Log on as : localSystem
Executable path : C:\Windows\system32\TieringEngineService.exe

TimeBrokerSvc startup parameters :
Display name : Time Broker
Service name : TimeBrokerSvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted

Tomcat9 startup parameters :
Display name : Apache Tomcat 9.0 Tomcat9
Service name : Tomcat9
Log on as : NT Authority\LocalService
Executable path : D:\XTPL\Tomcat\bin\Tomcat9.exe //RS//Tomcat9
Dependencies : Tcpip/Afd/

TrustedInstaller startup parameters :
Display name : Windows Modules Installer
Service name : TrustedInstaller
Log on as : localSystem
Executable path : C:\Windows\servicing\TrustedInstaller.exe

UI0Detect startup parameters :
Display name : Interactive Services Detection
Service name : UI0Detect
Log on as : LocalSystem
Executable path : C:\Windows\system32\UI0Detect.exe

UmRdpService startup parameters :
Display name : Remote Desktop Services UserMode Port Redirector
Service name : UmRdpService
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : TermService/RDPDR/

UnistoreSvc_d0c32 startup parameters :
Display name : User Data Storage_d0c32
Service name : UnistoreSvc_d0c32
Executable path : C:\Windows\System32\svchost.exe -k UnistackSvcGroup

UserDataSvc_d0c32 startup parameters :
Display name : User Data Access_d0c32
Service name : UserDataSvc_d0c32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

UsoSvc startup parameters :
Display name : Update Orchestrator Service for Windows Update
Service name : UsoSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

VSS startup parameters :
Display name : Volume Shadow Copy
Service name : VSS
Log on as : LocalSystem
Executable path : C:\Windows\system32\vssvc.exe
Dependencies : RPCSS/

VaultSvc startup parameters :
Display name : Credential Manager
Service name : VaultSvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\lsass.exe
Dependencies : rpcss/

W32Time startup parameters :
Display name : Windows Time
Service name : W32Time
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

WAS startup parameters :
Display name : Windows Process Activation Service
Service name : WAS
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k iissvcs
Dependencies : RPCSS/

WEPHOSTSVC startup parameters :
Display name : Windows Encryption Provider Host Service
Service name : WEPHOSTSVC
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k WepHostSvcGroup
Dependencies : rpcss/

WPDBusEnum startup parameters :
Display name : Portable Device Enumerator Service
Service name : WPDBusEnum
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WalletService startup parameters :
Display name : WalletService
Service name : WalletService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k appmodel

WdiServiceHost startup parameters :
Display name : Diagnostic Service Host
Service name : WdiServiceHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService

WdiSystemHost startup parameters :
Display name : Diagnostic System Host
Service name : WdiSystemHost
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

Wecsvc startup parameters :
Display name : Windows Event Collector
Service name : Wecsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\system32\svchost.exe -k NetworkService
Dependencies : HTTP/Eventlog/

WerSvc startup parameters :
Display name : Windows Error Reporting Service
Service name : WerSvc
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k WerSvcGroup

WiaRpc startup parameters :
Display name : Still Image Acquisition Events
Service name : WiaRpc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

WinHttpAutoProxySvc startup parameters :
Display name : WinHTTP Web Proxy Auto-Discovery Service
Service name : WinHttpAutoProxySvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService
Dependencies : Dhcp/

WpnUserService_d0c32 startup parameters :
Display name : Windows Push Notifications User Service_d0c32
Service name : WpnUserService_d0c32
Executable path : C:\Windows\system32\svchost.exe -k UnistackSvcGroup

XblAuthManager startup parameters :
Display name : Xbox Live Auth Manager
Service name : XblAuthManager
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

XblGameSave startup parameters :
Display name : Xbox Live Game Save
Service name : XblGameSave
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : UserManager/XblAuthManager/

aspnet_state startup parameters :
Display name : ASP.NET State Service
Service name : aspnet_state
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

bthserv startup parameters :
Display name : Bluetooth Support Service
Service name : bthserv
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

defragsvc startup parameters :
Display name : Optimize drives
Service name : defragsvc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k defragsvc
Dependencies : RPCSS/

diagnosticshub.standardcollector.service startup parameters :
Display name : Microsoft (R) Diagnostics Hub Standard Collector Service
Service name : diagnosticshub.standardcollector.service
Log on as : LocalSystem
Executable path : C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe

dmwappushservice startup parameters :
Display name : dmwappushsvc
Service name : dmwappushservice
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

dot3svc startup parameters :
Display name : Wired AutoConfig
Service name : dot3svc
Log on as : localSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/Ndisuio/Eaphost/

embeddedmode startup parameters :
Display name : Embedded Mode
Service name : embeddedmode
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : BrokerInfrastructure/

fdPHost startup parameters :
Display name : Function Discovery Provider Host
Service name : fdPHost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService
Dependencies : RpcSs/http/

hidserv startup parameters :
Display name : Human Interface Device Service
Service name : hidserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

icssvc startup parameters :
Display name : Windows Mobile Hotspot Service
Service name : icssvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : RpcSs/wcmsvc/

ksnproxy startup parameters :
Display name : Kaspersky Security Network proxy server
Service name : ksnproxy
Log on as : NT SERVICE\ksnproxy
Executable path : "C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\ksnproxy.exe"

lfsvc startup parameters :
Display name : Geolocation Service
Service name : lfsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

lltdsvc startup parameters :
Display name : Link-Layer Topology Discovery Mapper
Service name : lltdsvc
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService
Dependencies : rpcss/lltdio/

lmhosts startup parameters :
Display name : TCP/IP NetBIOS Helper
Service name : lmhosts
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : Afd/

msiserver startup parameters :
Display name : Windows Installer
Service name : msiserver
Log on as : LocalSystem
Executable path : C:\Windows\system32\msiexec.exe /V
Dependencies : rpcss/

netprofm startup parameters :
Display name : Network List Service
Service name : netprofm
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalService
Dependencies : RpcSs/nlasvc/

ose startup parameters :
Display name : Office Source Engine
Service name : ose
Log on as : LocalSystem
Executable path : "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"

osppsvc startup parameters :
Display name : Office Software Protection Platform
Service name : osppsvc
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
Dependencies : RpcSs/

pla startup parameters :
Display name : Performance Logs & Alerts
Service name : pla
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
Dependencies : RPCSS/

sacsvr startup parameters :
Display name : Special Administration Console Helper
Service name : sacsvr
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs

seclogon startup parameters :
Display name : Secondary Logon
Service name : seclogon
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs

smphost startup parameters :
Display name : Microsoft Storage Spaces SMP
Service name : smphost
Log on as : NT AUTHORITY\NetworkService
Executable path : C:\Windows\System32\svchost.exe -k smphost
Dependencies : RPCSS/

stisvc startup parameters :
Display name : Windows Image Acquisition (WIA)
Service name : stisvc
Log on as : NT Authority\LocalService
Executable path : C:\Windows\system32\svchost.exe -k imgsvc
Dependencies : RpcSs/

svsvc startup parameters :
Display name : Spot Verifier
Service name : svsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

swprv startup parameters :
Display name : Microsoft Software Shadow Copy Provider
Service name : swprv
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k swprv
Dependencies : RPCSS/

tzautoupdate startup parameters :
Display name : Auto Time Zone Updater
Service name : tzautoupdate
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalService

upnphost startup parameters :
Display name : UPnP Device Host
Service name : upnphost
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : SSDPSRV/HTTP/

vds startup parameters :
Display name : Virtual Disk
Service name : vds
Log on as : LocalSystem
Executable path : C:\Windows\System32\vds.exe
Dependencies : RpcSs/

vmicguestinterface startup parameters :
Display name : Hyper-V Guest Service Interface
Service name : vmicguestinterface
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicheartbeat startup parameters :
Display name : Hyper-V Heartbeat Service
Service name : vmicheartbeat
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService

vmickvpexchange startup parameters :
Display name : Hyper-V Data Exchange Service
Service name : vmickvpexchange
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicrdv startup parameters :
Display name : Hyper-V Remote Desktop Virtualization Service
Service name : vmicrdv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k ICService

vmicshutdown startup parameters :
Display name : Hyper-V Guest Shutdown Service
Service name : vmicshutdown
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

vmictimesync startup parameters :
Display name : Hyper-V Time Synchronization Service
Service name : vmictimesync
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Dependencies : VmGid/

vmicvmsession startup parameters :
Display name : Hyper-V PowerShell Direct Service
Service name : vmicvmsession
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

vmicvss startup parameters :
Display name : Hyper-V Volume Shadow Copy Requestor
Service name : vmicvss
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

w3logsvc startup parameters :
Display name : W3C Logging Service
Service name : w3logsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k apphost
Dependencies : HTTP/

wercplsupport startup parameters :
Display name : Problem Reports and Solutions Control Panel Support
Service name : wercplsupport
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs

wisvc startup parameters :
Display name : Windows Insider Service
Service name : wisvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

wlidsvc startup parameters :
Display name : Microsoft Account Sign-in Assistant
Service name : wlidsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : RpcSs/

wmiApSrv startup parameters :
Display name : WMI Performance Adapter
Service name : wmiApSrv
Log on as : localSystem
Executable path : C:\Windows\system32\wbem\WmiApSrv.exe

wuauserv startup parameters :
Display name : Windows Update
Service name : wuauserv
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k netsvcs
Dependencies : rpcss/

wudfsvc startup parameters :
Display name : Windows Driver Foundation - User-mode Driver Framework
Service name : wudfsvc
Log on as : LocalSystem
Executable path : C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : WudfPf/

The following services are disabled :

AppVClient startup parameters :
Display name : Microsoft App-V Client
Service name : AppVClient
Log on as : LocalSystem
Executable path : C:\Windows\system32\AppVClient.exe
Dependencies : RpcSS/netprofm/AppvVfs/AppVStrm/

Browser startup parameters :
Display name : Computer Browser
Service name : Browser
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k smbsvcs
Dependencies : LanmanWorkstation/LanmanServer/

CscService startup parameters :
Display name : Offline Files
Service name : CscService
Log on as : LocalSystem
Executable path : C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Dependencies : RpcSs/

NetMsmqActivator startup parameters :
Display name : Net.Msmq Listener Adapter
Service name : NetMsmqActivator
Log on as : NT AUTHORITY\NetworkService
Executable path : "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator
Dependencies : was/msmq/

RemoteAccess startup parameters :
Display name : Routing and Remote Access
Service name : RemoteAccess
Log on as : localSystem
Executable path : C:\Windows\System32\svchost.exe -k netsvcs
Dependencies : RpcSS/Bfe/RasMan/Http/+NetBIOSGroup/

SCardSvr startup parameters :
Display name : Smart Card
Service name : SCardSvr
Log on as : NT AUTHORITY\LocalService
Executable path : C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Dependencies : wudfsvc/

SQLAgent$SQLEXPRESS startup parameters :
Display name : SQL Server Agent (SQLEXPRESS)
Service name : SQLAgent$SQLEXPRESS
Log on as : NT AUTHORITY\NETWORKSERVICE
Executable path : "C:\Program Files\Microsoft SQL Server\MSSQL13.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS
Dependencies : MSSQL$SQLEXPRESS/

UevAgentService startup parameters :
Display name : User Experience Virtualization Service
Service name : UevAgentService
Log on as : LocalSystem
Executable path : C:\Windows\system32\AgentService.exe

WSearch startup parameters :
Display name : Windows Search
Service name : WSearch
Log on as : LocalSystem
Executable path : C:\Windows\system32\SearchIndexer.exe /Embedding
Dependencies : RPCSS/

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/139/smb


An SMB server is running on this port.

11011 - Microsoft Windows SMB Service Detection
-
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output

tcp/445/cifs


A CIFS server is running on this port.
10456 - Microsoft Windows SMB Service Enumeration
-
Synopsis
It is possible to enumerate remote services.
Description
This plugin implements the SvcOpenSCManager() and SvcEnumServices() calls to obtain, using the SMB protocol, the list of active and inactive services of the remote host.

An attacker may use this feature to gain better knowledge of the remote host.
Solution
To prevent the listing of the services from being obtained, you should either have tight login restrictions, so that only trusted users can access your host, and/or you should filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0751
Plugin Information
Published: 2000/07/03, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Active Services :

Application Host Helper Service [ AppHostSvc ]
Kaspersky Endpoint Security Service (KES.21.15) [ AVP.KES.21.15 ]
Kaspersky Seamless Update Service (KES.21.15) [ avpsus.KES.21.15 ]
Base Filtering Engine [ BFE ]
Background Tasks Infrastructure Service [ BrokerInfrastructure ]
Certificate Propagation [ CertPropSvc ]
COM+ System Application [ COMSysApp ]
CoreMessaging [ CoreMessagingRegistrar ]
Cryptographic Services [ CryptSvc ]
DCOM Server Process Launcher [ DcomLaunch ]
DHCP Client [ Dhcp ]
Connected User Experiences and Telemetry [ DiagTrack ]
DNS Client [ Dnscache ]
Diagnostic Policy Service [ DPS ]
Windows Event Log [ EventLog ]
COM+ Event System [ EventSystem ]
Windows Font Cache Service [ FontCache ]
Group Policy Client [ gpsvc ]
IKE and AuthIP IPsec Keying Modules [ IKEEXT ]
IP Helper [ iphlpsvc ]
CNG Key Isolation [ KeyIso ]
Kaspersky Security Center Network Agent [ klnagent ]
Server [ LanmanServer ]
Workstation [ LanmanWorkstation ]
Geolocation Service [ lfsvc ]
Windows License Manager Service [ LicenseManager ]
TCP/IP NetBIOS Helper [ lmhosts ]
Local Session Manager [ LSM ]
Windows Firewall [ MpsSvc ]
Distributed Transaction Coordinator [ MSDTC ]
SQL Server Integration Services 15.0 [ MsDtsServer150 ]
SQL Server (SQLEXPRESS) [ MSSQL$SQLEXPRESS ]
SQL Full-text Filter Daemon Launcher (MSSQLSERVER) [ MSSQLFDLauncher ]
SQL Server Launchpad (MSSQLSERVER) [ MSSQLLaunchpad ]
SQL Server (MSSQLSERVER) [ MSSQLSERVER ]
SQL Server Analysis Services (MSSQLSERVER) [ MSSQLServerOLAPService ]
Network Connection Broker [ NcbService ]
Net.Pipe Listener Adapter [ NetPipeActivator ]
Network List Service [ netprofm ]
Net.Tcp Listener Adapter [ NetTcpActivator ]
Net.Tcp Port Sharing Service [ NetTcpPortSharing ]
Network Location Awareness [ NlaSvc ]
Network Store Interface Service [ nsi ]
nxlog [ nxlog ]
Office Software Protection Platform [ osppsvc ]
Program Compatibility Assistant Service [ PcaSvc ]
Plug and Play [ PlugPlay ]
IPsec Policy Agent [ PolicyAgent ]
Power [ Power ]
User Profile Service [ ProfSvc ]
Remote Registry [ RemoteRegistry ]
RPC Endpoint Mapper [ RpcEptMapper ]
Remote Procedure Call (RPC) [ RpcSs ]
Security Accounts Manager [ SamSs ]
Smart Card Device Enumeration Service [ ScDeviceEnum ]
Task Scheduler [ Schedule ]
System Event Notification Service [ SENS ]
Remote Desktop Configuration [ SessionEnv ]
Shell Hardware Detection [ ShellHWDetection ]
Print Spooler [ Spooler ]
Software Protection [ sppsvc ]
SQL Server Browser [ SQLBrowser ]
SQL Server Agent (MSSQLSERVER) [ SQLSERVERAGENT ]
SQL Server CEIP service (MSSQLSERVER) [ SQLTELEMETRY ]
SQL Server CEIP service (SQLEXPRESS) [ SQLTELEMETRY$SQLEXPRESS ]
SQL Server VSS Writer [ SQLWriter ]
SQL Server Analysis Services CEIP (MSSQLSERVER) [ SSASTELEMETRY ]
SSDP Discovery [ SSDPSRV ]
SQL Server Integration Services CEIP service 15.0 [ SSISTELEMETRY150 ]
State Repository Service [ StateRepository ]
Storage Service [ StorSvc ]
System Events Broker [ SystemEventsBroker ]
Remote Desktop Services [ TermService ]
Themes [ Themes ]
Tile Data model server [ tiledatamodelsvc ]
Time Broker [ TimeBrokerSvc ]
Distributed Link Tracking Client [ TrkWks ]
Windows Modules Installer [ TrustedInstaller ]
User Access Logging Service [ UALSVC ]
Remote Desktop Services UserMode Port Redirector [ UmRdpService ]
User Manager [ UserManager ]
Credential Manager [ VaultSvc ]
World Wide Web Publishing Service [ W3SVC ]
Windows Process Activation Service [ WAS ]
Windows Connection Manager [ Wcmsvc ]
WinHTTP Web Proxy Auto-Discovery Service [ WinHttpAutoProxySvc ]
Windows Management Instrumentation [ Winmgmt ]
Windows Remote Management (WS-Management) [ WinRM ]
VNC Server Version 4 [ WinVNC4 ]
Windows Push Notifications System Service [ WpnService ]
Windows Driver Foundation - User-mode Driver Framework [ wudfsvc ]
CDPUserSvc_d0c32 [ CDPUserSvc_d0c32 ]
Sync Host_d0c32 [ OneSyncSvc_d0c32 ]

Inactive Services :

AllJoyn Router Service [ AJRouter ]
Application Layer Gateway Service [ ALG ]
Application Identity [ AppIDSvc ]
Application Information [ Appinfo ]
Application Management [ AppMgmt ]
App Readiness [ AppReadiness ]
Microsoft App-V Client [ AppVClient ]
AppX Deployment Service (AppXSVC) [ AppXSvc ]
ASP.NET State Service [ aspnet_state ]
Windows Audio Endpoint Builder [ AudioEndpointBuilder ]
Windows Audio [ Audiosrv ]
ActiveX Installer (AxInstSV) [ AxInstSV ]
Background Intelligent Transfer Service [ BITS ]
Computer Browser [ Browser ]
Bluetooth Support Service [ bthserv ]
Connected Devices Platform Service [ CDPSvc ]
Client License Service (ClipSVC) [ ClipSVC ]
Offline Files [ CscService ]
DataCollectionPublishingService [ DcpSvc ]
Optimize drives [ defragsvc ]
Device Association Service [ DeviceAssociationService ]
Device Install Service [ DeviceInstall ]
DevQuery Background Discovery Broker [ DevQueryBroker ]
Microsoft (R) Diagnostics Hub Standard Collector Service [ diagnosticshub.standardcollector.service ]
Device Management Enrollment Service [ DmEnrollmentSvc ]
dmwappushsvc [ dmwappushservice ]
Wired AutoConfig [ dot3svc ]
Device Setup Manager [ DsmSvc ]
Data Sharing Service [ DsSvc ]
Extensible Authentication Protocol [ Eaphost ]
Encrypting File System (EFS) [ EFS ]
Embedded Mode [ embeddedmode ]
Enterprise App Management Service [ EntAppSvc ]
Function Discovery Provider Host [ fdPHost ]
Function Discovery Resource Publication [ FDResPub ]
Windows Presentation Foundation Font Cache 3.0.0.0 [ FontCache3.0.0.0 ]
Windows Camera Frame Server [ FrameServer ]
Google Chrome Elevation Service (GoogleChromeElevationService) [ GoogleChromeElevationService ]
Google Updater Internal Service (GoogleUpdaterInternalService144.0.7547.4) [ GoogleUpdaterInternalService144.0.7547.4 ]
Google Updater Service (GoogleUpdaterService144.0.7547.4) [ GoogleUpdaterService144.0.7547.4 ]
Human Interface Device Service [ hidserv ]
HV Host Service [ HvHost ]
Windows Mobile Hotspot Service [ icssvc ]
KDC Proxy Server service (KPS) [ KPSSVC ]
Kaspersky Security Network proxy server [ ksnproxy ]
KtmRm for Distributed Transaction Coordinator [ KtmRm ]
Link-Layer Topology Discovery Mapper [ lltdsvc ]
Downloaded Maps Manager [ MapsBroker ]
Microsoft iSCSI Initiator Service [ MSiSCSI ]
Windows Installer [ msiserver ]
MS-MPI Launch Service [ MsMpiLaunchSvc ]
Network Connectivity Assistant [ NcaSvc ]
Netlogon [ Netlogon ]
Network Connections [ Netman ]
Net.Msmq Listener Adapter [ NetMsmqActivator ]
Network Setup Service [ NetSetupSvc ]
Microsoft Passport Container [ NgcCtnrSvc ]
Microsoft Passport [ NgcSvc ]
Office Source Engine [ ose ]
Performance Counter DLL Host [ PerfHost ]
Phone Service [ PhoneSvc ]
Performance Logs & Alerts [ pla ]
Printer Extensions and Notifications [ PrintNotify ]
Quality Windows Audio Video Experience [ QWAVE ]
Remote Access Auto Connection Manager [ RasAuto ]
Remote Access Connection Manager [ RasMan ]
Routing and Remote Access [ RemoteAccess ]
Radio Management Service [ RmSvc ]
Remote Procedure Call (RPC) Locator [ RpcLocator ]
Resultant Set of Policy Provider [ RSoPProv ]
Special Administration Console Helper [ sacsvr ]
Smart Card [ SCardSvr ]
Smart Card Removal Policy [ SCPolicySvc ]
Secondary Logon [ seclogon ]
Sensor Data Service [ SensorDataService ]
Sensor Service [ SensorService ]
Sensor Monitoring Service [ SensrSvc ]
Internet Connection Sharing (ICS) [ SharedAccess ]
Microsoft Storage Spaces SMP [ smphost ]
SNMP Trap [ SNMPTRAP ]
SQL Server Agent (SQLEXPRESS) [ SQLAgent$SQLEXPRESS ]
Secure Socket Tunneling Protocol Service [ SstpSvc ]
Windows Image Acquisition (WIA) [ stisvc ]
Spot Verifier [ svsvc ]
Microsoft Software Shadow Copy Provider [ swprv ]
Superfetch [ SysMain ]
Touch Keyboard and Handwriting Panel Service [ TabletInputService ]
Telephony [ TapiSrv ]
Storage Tiers Management [ TieringEngineService ]
Apache Tomcat 9.0 Tomcat9 [ Tomcat9 ]
Auto Time Zone Updater [ tzautoupdate ]
User Experience Virtualization Service [ UevAgentService ]
Interactive Services Detection [ UI0Detect ]
UPnP Device Host [ upnphost ]
Update Orchestrator Service for Windows Update [ UsoSvc ]
Virtual Disk [ vds ]
Hyper-V Guest Service Interface [ vmicguestinterface ]
Hyper-V Heartbeat Service [ vmicheartbeat ]
Hyper-V Data Exchange Service [ vmickvpexchange ]
Hyper-V Remote Desktop Virtualization Service [ vmicrdv ]
Hyper-V Guest Shutdown Service [ vmicshutdown ]
Hyper-V Time Synchronization Service [ vmictimesync ]
Hyper-V PowerShell Direct Service [ vmicvmsession ]
Hyper-V Volume Shadow Copy Requestor [ vmicvss ]
Volume Shadow Copy [ VSS ]
Windows Time [ W32Time ]
W3C Logging Service [ w3logsvc ]
WalletService [ WalletService ]
Windows Biometric Service [ WbioSrvc ]
Diagnostic Service Host [ WdiServiceHost ]
Diagnostic System Host [ WdiSystemHost ]
Windows Event Collector [ Wecsvc ]
Windows Encryption Provider Host Service [ WEPHOSTSVC ]
Problem Reports and Solutions Control Panel Support [ wercplsupport ]
Windows Error Reporting Service [ WerSvc ]
Still Image Acquisition Events [ WiaRpc ]
Windows Insider Service [ wisvc ]
Microsoft Account Sign-in Assistant [ wlidsvc ]
WMI Performance Adapter [ wmiApSrv ]
Portable Device Enumerator Service [ WPDBusEnum ]
Windows Search [ WSearch ]
Windows Update [ wuauserv ]
Xbox Live Auth Manager [ XblAuthManager ]
Xbox Live Game Save [ XblGameSave ]
Contact Data_d0c32 [ PimIndexMaintenanceSvc_d0c32 ]
User Data Storage_d0c32 [ UnistoreSvc_d0c32 ]
User Data Access_d0c32 [ UserDataSvc_d0c32 ]
Windows Push Notifications User Service_d0c32 [ WpnUserService_d0c32 ]

92373 - Microsoft Windows SMB Sessions
-
Synopsis
Nessus was able to collect and report SMB session information from the remote host.
Description
Nessus was able to collect details of SMB sessions from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2025/12/15
Plugin Output

tcp/0

tidua

Extended SMB session information attached.

23974 - Microsoft Windows SMB Share Hosting Office Files
-
Synopsis
The remote share contains Office-related files.
Description
This plugin connects to the remotely accessible SMB shares and attempts to find office related files (such as .doc, .ppt, .xls, .pdf etc).
Solution
Make sure that the files containing confidential information have proper access controls set on them.
Risk Factor
None
Plugin Information
Published: 2007/01/04, Modified: 2011/03/21
Plugin Output

tcp/445/cifs


Here is a list of office files which have been found on the remote SMB
shares :

+ D$ :

- \files\scrip\scrip.doc
- \files\scrip\scrip_standardised_format.doc
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$rxvqcdb.xls
- \files\mtf_varmarginreport (1).xls
- \files\var240924.xls
- \files\var250924.xls
- \new folder\mtf_varmarginreport.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39\downloads\var090126.xls
- \xtpl\apps\xhawkeye client_old\filedata\dfd.xls
- \xtpl\apps\xhawkeye client_old\filedata\err.xls
- \xtpl\apps\xhawkeye client_old\filedata\qqq.xls
- \xtpl\apps\xhawkeye server 2.2.0.32 new\downloads\mtf_varmarginreport.xls
- \xtpl\apps\xhawkeye server 2.2.0.32 new\downloads\var030924.xls
- \xtpl\apps\xhawkeye server 2.2.0.53\downloads\var171224.xls
- \xtpl\apps\xhawkeye server_1.0.0.207\downloads\mtf_varmarginreport.xls
- \xtpl\apps\xhawkeye server_1.0.0.207\downloads\var080126.xls
- \xtpl\apps\xhawkeye server_1.0.0.207\downloads\var090126.xls
- \xtpl\transfer\mtf_ageing_666121537_06022025121537.xls
- \xtpl\apps\xhawkeye server 2.2.0.53\downloads\var161224.xls
- \xtpl\apps\xhawkeye server 2.2.0.53\downloads\mtf_varmarginreport.xls
- \xtpl\apps\xhawkeye server 2.2.0.38\downloads\var171224.xls
- \xtpl\apps\xhawkeye server 2.2.0.38\downloads\var161224.xls
- \xtpl\apps\xhawkeye server 2.2.0.38\downloads\mtf_varmarginreport.xls
- \xtpl\apps\xhawkeye server 2.2.0.32 new\downloads\var040924.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39\downloads\var080126.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39\downloads\mtf_varmarginreport.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39 - copy\downloads\var240325.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39 - copy\downloads\var210325.xls
- \xtpl\apps\uat\xhawkeye server 2.2.0.39 - copy\downloads\mtf_varmarginreport.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$r3tpnpg.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$r0yf2ta.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$ixvqcdb.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$i3tpnpg.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$i0yf2ta.xls
- \02072025\eligible securities and corporate bonds collateral deposits for july'202.._.xlsx
- \xtpl\apps\xhawkeye client_old\filedata\risk.xlsx

+ C$ :

- \program files (x86)\microsoft office\office14\1033\prottpln.doc
- \windows\syswow64\msdrm\msoirmprotector.doc
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.doc
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.doc
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.doc
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.doc
- \windows\system32\msdrm\msoirmprotector.doc
- \users\administrator\desktop\new folder\scrip\scrip_standardised_format.doc
- \users\administrator\desktop\new folder\scrip\scrip.doc
- \users\administrator\desktop\20122025\scrip\scrip_standardised_format.doc
- \users\administrator\desktop\20122025\scrip\scrip.doc
- \program files (x86)\microsoft office\office14\1033\prottplv.doc
- \program files (x86)\microsoft office\office14\1033\prottpln.ppt
- \program files (x86)\microsoft office\office14\1033\prottplv.ppt
- \windows\system32\msdrm\msoirmprotector.ppt
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.ppt
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.ppt
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.ppt
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.ppt
- \windows\syswow64\msdrm\msoirmprotector.ppt
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$ia82998.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$ra82998.xls
- \users\administrator\desktop\new folder\var181225.xls
- \users\administrator\desktop\new folder\var191225.xls
- \users\administrator\downloads\cash.xls
- \users\administrator\downloads\var121225.xls
- \users\administrator\downloads\var151225.xls
- \windows\system32\msdrm\msoirmprotector.xls
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_8de1f0fd846cf8f4\msoirmprotector.xls
- \windows\winsxs\wow64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_4594460740901c48\msoirmprotector.xls
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.4169_none_838d46ab500c36f9\msoirmprotector.xls
- \windows\winsxs\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_10.0.14393.0_none_3b3f9bb50c2f5a4d\msoirmprotector.xls
- \windows\syswow64\msdrm\msoirmprotector.xls
- \users\administrator\desktop\new folder\mtf margin shortfall 18-12-2025.xls
- \users\administrator\desktop\20122025\var151225.xls
- \users\administrator\desktop\20122025\var121225.xls
- \program files (x86)\microsoft office\office14\samples\solvsamp.xls
- \program files (x86)\microsoft office\office14\1033\prottplv.xls
- \program files (x86)\microsoft office\office14\1033\prottpln.xls
- \$recycle.bin\s-1-5-21-3119273522-2427777209-1705870880-500\$rlm1svo\mtf_ageing_666072522_08122025072523.xlsx
- \users\administrator\appdata\local\microsoft\windows\inetcache\content.mso\aa59a34c.xlsx
- \users\administrator\appdata\roaming\microsoft\windows\recent\alloc all 23092025.xlsx
- \users\administrator\desktop\45854396.xlsx
- \users\administrator\desktop\before peak mrg calc with hw ledger_1_28032025.xlsx
- \users\administrator\documents\12014167 logs.xlsx
- \users\administrator\documents\123.xlsx
- \users\administrator\documents\12345.xlsx
- \users\administrator\documents\16020125.xlsx
- \users\administrator\documents\24092025 logs.xlsx
- \users\administrator\documents\45854396.xlsx
- \users\administrator\documents\50778.xlsx
- \users\administrator\documents\900001666.xlsx
- \users\administrator\documents\all all 01072025.xlsx
- \users\administrator\documents\all all 01082025.xlsx
- \users\administrator\documents\all all 01092025.xlsx
- \users\administrator\documents\all all 01102025.xlsx
- \users\administrator\documents\all all 01102025123.xlsx
- \users\administrator\documents\all all 01122025.xlsx
- \users\administrator\documents\all all 02012026.xlsx
- \users\administrator\documents\all all 02072025.xlsx
- \users\administrator\documents\all all 04082025.xlsx
- \users\administrator\documents\all all 04092025.xlsx
- \users\administrator\documents\all all 04112025.xlsx
- \users\administrator\documents\all all 04122025.xlsx
- \users\administrator\documents\all all 05012026.xlsx
- \users\administrator\documents\all all 05082025.xlsx
- \users\administrator\documents\all all 05092025.xlsx
- \users\administrator\documents\all all 05112025.xlsx
- \users\administrator\documents\all all 07112025.xlsx
- \users\administrator\documents\all all 08012026.xlsx
- \users\administrator\documents\all all 08072025.xlsx
- \users\administrator\documents\all all 08082025.xlsx
- \users\administrator\documents\all all 08092025.xlsx
- \users\administrator\documents\all all 08102025.xlsx
- \users\administrator\documents\all all 08122025.xlsx
- \users\administrator\documents\all all 09012026.xlsx
- \users\administrator\documents\all all 10112025.xlsx
- \users\administrator\documents\all all 10122025.xlsx
- \users\administrator\documents\all all 11072025.xlsx
- \users\administrator\documents\all all 11082025.xlsx
- \users\administrator\documents\all all 11092025.xlsx
- \users\administrator\documents\all all 11112025.xlsx
- \users\administrator\documents\all all 11122025.xlsx
- \users\administrator\documents\all all 12062025.xlsx
- \users\administrator\documents\all all 14072025.xlsx
- \users\administrator\documents\all all 14082025.xlsx
- \users\administrator\documents\all all 14102025.xlsx
- \users\administrator\documents\all all 14112025.xlsx
- \users\administrator\documents\all all 15072025.xlsx
- \users\administrator\documents\all all 15092025.xlsx
- \users\administrator\documents\all all 15102025.xlsx
- \users\administrator\documents\all all 15122025.xlsx
- \users\administrator\documents\all all 17102025.xlsx
- \users\administrator\documents\all all 17112025.xlsx
- \users\administrator\documents\all all 17122025.xlsx
- \users\administrator\documents\all all 18062025.xlsx
- \users\administrator\documents\all all 18072025.xlsx
- \users\administrator\documents\all all 18082025.xlsx
- \users\administrator\documents\all all 18092025.xlsx
- \users\administrator\documents\all all 18112025.xlsx
- \users\administrator\documents\all all 20112025.xlsx
- \users\administrator\documents\all all 21072025.xlsx
- \users\administrator\documents\all all 21082025.xlsx
- \users\administrator\documents\all all 21102025.xlsx
- \users\administrator\documents\all all 21112025.xlsx
- \users\administrator\documents\all all 22072025.xlsx
- \users\administrator\documents\all all 22082025.xlsx
- \users\administrator\documents\all all 22092025.xlsx
- \users\administrator\documents\all all 24102025.xlsx
- \users\administrator\documents\all all 24112025.xlsx
- \users\administrator\documents\all all 24122025.xlsx
- \users\administrator\documents\all all 25062025.xlsx
- \users\administrator\documents\all all 25072025.xlsx
- \users\administrator\documents\all all 25082025.xlsx
- \users\administrator\documents\all all 25092025.xlsx
- \users\administrator\documents\all all 25102025.xlsx
- \users\administrator\documents\all all 27112025.xlsx
- \users\administrator\documents\all all 28072025.xlsx
- \users\administrator\documents\all all 28082025.xlsx
- \users\administrator\documents\all all 28102025.xlsx
- \users\administrator\documents\all all 28112025.xlsx
- \users\administrator\documents\all all 29072025.xlsx
- \users\administrator\documents\all all 29082025.xlsx
- \users\administrator\documents\all all 29092025.xlsx
- \users\administrator\documents\all all 31102025.xlsx
- \users\administrator\documents\all all 31122025.xlsx
- \users\administrator\documents\all all new 190825.xlsx
- \users\administrator\documents\all all old 19082025.xlsx
- \users\administrator\documents\all all_02062025.xlsx
- \users\administrator\documents\all all_04062025.xlsx
- \users\administrator\documents\all all_05062025.xlsx
- \users\administrator\documents\all all_06062025.xlsx
- \users\administrator\documents\all all_30052025.xlsx
- \users\administrator\documents\all deac 02062025.xlsx
- \users\administrator\documents\all deac 09062025.xlsx
- \users\administrator\documents\all deac 10062025.xlsx
- \users\administrator\documents\all deac 27052025.xlsx
- \users\administrator\documents\all deac 29052025.xlsx
- \users\administrator\documents\all deac 30052025.xlsx
- \users\administrator\documents\all deacr 10122025.xlsx
- \users\administrator\documents\all deall_02122024.xlsx
- \users\administrator\documents\all deall_03012025.xlsx
- \users\administrator\documents\all deall_03022025.xlsx
- \users\administrator\documents\all deall_03032025.xlsx
- \users\administrator\documents\all deall_03042025.xlsx
- \users\administrator\documents\all deall_03102024.xlsx
- \users\administrator\documents\all deall_03122024.xlsx
- \users\administrator\documents\all deall_04022025.xlsx
- \users\administrator\documents\all deall_05112024.xlsx
- \users\administrator\documents\all deall_05122024.xlsx
- \users\administrator\documents\all deall_06012025.xlsx
- \users\administrator\documents\all deall_06022025.xlsx
- \users\administrator\documents\all deall_06032025.xlsx
- \users\administrator\documents\all deall_06052025.xlsx
- \users\administrator\documents\all deall_06112024.xlsx
- \users\administrator\documents\all deall_06122024.xlsx
- \users\administrator\documents\all deall_08042025.xlsx
- \users\administrator\documents\all deall_08102024.xlsx
- \users\administrator\documents\all deall_08112024.xlsx
- \users\administrator\documents\all deall_09012025.xlsx
- \users\administrator\documents\all deall_09042025.xlsx
- \users\administrator\documents\all deall_09052025.xlsx
- \users\administrator\documents\all deall_09092024.xlsx
- \users\administrator\documents\all deall_09102024.xlsx
- \users\administrator\documents\all deall_11032025.xlsx
- \users\administrator\documents\all deall_11042025.xlsx
- \users\administrator\documents\all deall_11092024.xlsx
- \users\administrator\documents\all deall_11102024.xlsx
- \users\administrator\documents\all deall_11112024.xlsx
- \users\administrator\documents\all deall_11122024.xlsx
- \users\administrator\documents\all deall_12022025.xlsx
- \users\administrator\documents\all deall_12032025.xlsx
- \users\administrator\documents\all deall_13092024.xlsx
- \users\administrator\documents\all deall_13112024.xlsx
- \users\administrator\documents\all deall_13122024.xlsx
- \users\administrator\documents\all deall_14012025.xlsx
- \users\administrator\documents\all deall_14022025.xlsx
- \users\administrator\documents\all deall_14052025.xlsx
- \users\administrator\documents\all deall_14102024.xlsx
- \users\administrator\documents\all deall_14112024.xlsx
- \users\administrator\documents\all deall_16122024.xlsx
- \users\administrator\documents\all deall_17012025.xlsx
- \users\administrator\documents\all deall_17022025.xlsx
- \users\administrator\documents\all deall_17032025.xlsx
- \users\administrator\documents\all deall_17042025.xlsx
- \users\administrator\documents\all deall_17092024.xlsx
- \users\administrator\documents\all deall_17102024.xlsx
- \users\administrator\documents\all deall_17122024.xlsx
- \users\administrator\documents\all deall_20012025.xlsx
- \users\administrator\documents\all deall_20022025.xlsx
- \users\administrator\documents\all deall_20032025.xlsx
- \users\administrator\documents\all deall_20052025.xlsx
- \users\administrator\documents\all deall_20092024.xlsx
- \users\administrator\documents\all deall_20122024.xlsx
- \users\administrator\documents\all deall_21012025.xlsx
- \users\administrator\documents\all deall_21022025.xlsx
- \users\administrator\documents\all deall_22102024.xlsx
- \users\administrator\documents\all deall_22112024.xlsx
- \users\administrator\documents\all deall_23012025.xlsx
- \users\administrator\documents\all deall_23042025.xlsx
- \users\administrator\documents\all deall_23052025.xlsx
- \users\administrator\documents\all deall_23082024.xlsx
- \users\administrator\documents\all deall_23092024.xlsx
- \users\administrator\documents\all deall_23102024.xlsx
- \users\administrator\documents\all deall_25042025.xlsx
- \users\administrator\documents\all deall_25092024.xlsx
- \users\administrator\documents\all deall_25102024.xlsx
- \users\administrator\documents\all deall_25112024.xlsx
- \users\administrator\documents\all deall_26032025.xlsx
- \users\administrator\documents\all deall_26052025.xlsx
- \users\administrator\documents\all deall_26092024.xlsx
- \users\administrator\documents\all deall_26122024.xlsx
- \users\administrator\documents\all deall_28032025.xlsx
- \users\administrator\documents\all deall_28042025.xlsx
- \users\administrator\documents\all deall_28102024.xlsx
- \users\administrator\documents\all deall_28112024.xlsx
- \users\administrator\documents\all deall_29012025.xlsx
- \users\administrator\documents\all deall_29042025.xlsx
- \users\administrator\documents\all deall_29102024.xlsx
- \users\administrator\documents\all deall_29112024.xlsx


Note that Nessus has limited the report to 255 files although there
may be more.
60119 - Microsoft Windows SMB Share Permissions Enumeration
-
Synopsis
It was possible to enumerate the permissions of remote network shares.
Description
By using the supplied credentials, Nessus was able to enumerate the permissions of network shares. User permissions are enumerated for each network share that has a list of access control entries (ACEs).
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/07/25, Modified: 2022/08/11
Plugin Output

tcp/445/cifs


Share path : \\XHWAKEYESRV\backup$
Local path : D:\backup
[*] Allow ACE for Everyone (S-1-1-0): 0x001200a9
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: NO
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: NO
FILE_ADD_FILE: NO
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: NO
DELETE: NO
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: NO
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: NO
FILE_CREATE_PIPE_INSTANCE: NO
FILE_WRITE_ATTRIBUTES: NO
[*] Allow ACE for XHWAKEYESRV\Production (S-1-5-21-3119273522-2427777209-1705870880-500): 0x001f01ff
MAXIMUM_ALLOWED: NO
FILE_TRAVERSE: YES
FILE_GENERIC_READ: YES
STANDARD_RIGHTS_ALL: YES
ACCESS_ALL: YES
FILE_LIST_DIRECTORY: YES
GENERIC_ALL: NO
FILE_DELETE_CHILD: YES
ACCESS_SYSTEM_SECURITY: NO
FILE_WRITE_EA: YES
FILE_ADD_FILE: YES
FILE_READ_EA: YES
FILE_READ_ATTRIBUTES: YES
STANDARD_RIGHTS_EXECUTE: YES
FILE_ALL_ACCESS: YES
GENERIC_READ: NO
WRITE_DAC: YES
DELETE: YES
ACCESS_GROUP: NO
STANDARD_RIGHTS_REQUIRED: YES
WRITE_OWNER: YES
FILE_GENERIC_EXECUTE: YES
GENERIC_WRITE: NO
SYNCHRONIZE: YES
FILE_GENERIC_WRITE: YES
FILE_CREATE_PIPE_INSTANCE: YES
FILE_WRITE_ATTRIBUTES: YES
10396 - Microsoft Windows SMB Shares Access
-
Synopsis
It is possible to access a network share.
Description
The remote has one or more Windows shares that can be accessed through the network with the given credentials.

Depending on the share rights, it may allow an attacker to read / write confidential data.
Solution
To restrict access under Windows, open Explorer, do a right click on each share, go to the 'sharing' tab, and click on 'permissions'.
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2021/10/04
Plugin Output

tcp/445/cifs


The following shares can be accessed as tidua :

- D$ - (readable,writable)
+ Content of this share :
02072025
backup
backup of 61
CC_CLND_030000_000001_I_202506300000_1.csv
cerft_Pass.txt
Eligible HW UPLOAD Securities and Corporate Bonds for July'2025.csv
files
IML-BSE-CM
LKPSOFT
MTF_APPROVED_July_30062025.csv
New folder
not to do epn 01072025.csv
ServerConf.cfg
ServerConf.zip
settlement.csv
symphony
System Volume Information
tmp
www.lkp.net.in_live_21042025-23052026.pfx
XTPL

- C$ - (readable,writable)
+ Content of this share :
bootmgr
BOOTNXT
cpqsystem
Documents and Settings
inetpub
MCX_20250425.rt
MSOCache
MySQLData_final_DBbackup08Mar2025.rar
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Recovery
SQLServer2016Media
System Volume Information
Users
Windows

- backup$ - (readable)
+ Content of this share :
..
Xhawkeye20260105550.bak
Xhawkeye20260106730.bak
Xhawkeye20260107730.bak
Xhawkeye20260108677.bak
Xhawkeye20260109143.bak
Xhawkeye_14102025_Live_DB.bak

- ADMIN$ - (readable,writable)
+ Content of this share :
..
ADFS
appcompat
AppPatch
AppReadiness
assembly
bcastdvr
bfsvc.exe
Boot
bootstat.dat
Branding
CbsTemp
Cluster
Cursors
debug
diagnostics
DigitalLocker
Downloaded Program Files
drivers
DtcInstall.log
ELAMBKUP
en-US
explorer.exe
Fonts
GameBarPresenceWriter
Globalization
Help
HelpPane.exe
hh.exe
iis.log
IME
ImmersiveControlPanel
INF
InfusedApps
InputMethod
Installer
L2Schemas
LiveKernelReports
Logs
lsasetup.log
Media
mib.bin
Microsoft.NET
Migration
MiracastView
ModemLogs
NetworkController
notepad.exe
OCR
Offline Web Pages
Panther
PCHEALTH
Performance
PFRO.log
PLA
PolicyDefinitions
prefetch
PrintDialog
Provisioning
regedit.exe
Registration
RemotePackages
rescache
Resources
SchCache
schemas
security
ServerDataCenter.xml
ServiceProfiles
servicing
Setup
setupact.log
setuperr.log
ShellExperiences
SHELLNEW
SKB
SoftwareDistribution
Speech
Speech_OneCore
splwow64.exe
System
system.ini
System32
SystemApps
SystemResources
SysWOW64
TAPI
Tasks
Temp
tracing
twain_32
twain_32.dll
Vss
Web
win.ini
WindowsShell.Manifest
10395 - Microsoft Windows SMB Shares Enumeration
-
Synopsis
It is possible to enumerate remote network shares.
Description
By connecting to the remote host, Nessus was able to enumerate the network share names.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Here are the SMB shares available on the remote host when logged in as tidua:

- ADMIN$
- backup$
- C$
- D$
- IPC$
100871 - Microsoft Windows SMB Versions Supported (remote check)
-
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.

Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output

tcp/445/cifs


The remote host supports the following versions of SMB :
SMBv1
SMBv2
106716 - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
-
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output

tcp/445/cifs


The remote host supports the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
3.0 Windows 8
3.0.2 Windows 8.1
3.1.1 Windows 10

The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.1 Windows 10

92368 - Microsoft Windows Scripting Host Settings
-
Synopsis
Nessus was able to collect and report the Windows scripting host settings from the remote host.
Description
Nessus was able to collect system and user level Windows scripting host settings from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\activedebugging : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\displaylogo : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\usewinsafer : 1
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\silentterminate : 0
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\activedebugging : 1

Windows scripting host configuration attached.

200493 - Microsoft Windows Start Menu Software Version Enumeration
-
Synopsis
Enumerates Start Menu software versions.
Description
This plugin enumerates the installed software version by interrogating information obtained from various registry entries and files on disk. This plugin provides a best guess at the software version and a confidence level for that version.

Note that the versions detected here do not necessarily indicate the actual installed version nor do they necessarily mean that the application is actually installed on the remote host. In some cases there may be artifacts left behind by uninstallers on the system.
Solution
Remove any applications that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2024/06/13, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The following software information is available on the remote host :

- Google Chrome.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Google Chrome.lnk
Target : C:\Program Files\Google\Chrome\Application\chrome.exe
Version : 143.0.7499.170

- Immersive Control Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Immersive Control Panel.lnk
Target : C:\Windows\System32\Control.exe
Version : 10.0.14393.0

- MiracastView.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\MiracastView.lnk
Target : C:\Windows\MiracastView\MiracastView.exe
Version : 10.0.14393.0

- Notepad++.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Notepad++.lnk
Target : C:\Program Files\Notepad++\notepad++.exe
Version : 8.6.6.0

- PrintDialog.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\PrintDialog.lnk
Target : C:\Windows\PrintDialog\PrintDialog.exe
Version : 10.0.14393.0

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.14393.2156

- Speech Recognition.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessibility\Speech Recognition.lnk
Target : C:\Windows\Speech\Common\sapisvr.exe
Version : 5.3.19915.0

- Calculator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Calculator.lnk
Target : C:\Windows\system32\win32calc.exe
Version : 10.0.14393.0

- Math Input Panel.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Math Input Panel.lnk
Target : C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe
Version : 10.0.14393.0

- Paint.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Paint.lnk
Target : C:\Windows\system32\mspaint.exe
Version : 10.0.14393.2273

- Remote Desktop Connection.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Remote Desktop Connection.lnk
Target : C:\Windows\system32\mstsc.exe
Version : 10.0.14393.2273

- Snipping Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Snipping Tool.lnk
Target : C:\Windows\system32\SnippingTool.exe
Version : 10.0.14393.0

- Steps Recorder.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Steps Recorder.lnk
Target : C:\Windows\system32\psr.exe
Version : 10.0.14393.0

- Windows Media Player.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Windows Media Player.lnk
Target : C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Version : 12.0.14393.82

- Wordpad.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\Wordpad.lnk
Target : C:\Program Files\Windows NT\Accessories\wordpad.exe
Version : 10.0.14393.1480

- Character Map.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Character Map.lnk
Target : C:\Windows\system32\charmap.exe
Version : 5.2.3668.0

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Accessories\System Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- Component Services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Component Services.lnk
Target : C:\Windows\system32\comexp.msc
Version : unknown

- Computer Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Computer Management.lnk
Target : C:\Windows\system32\compmgmt.msc
Version : unknown

- dfrgui.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\dfrgui.lnk
Target : C:\Windows\system32\dfrgui.exe
Version : 10.0.14393.0

- Disk Cleanup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Disk Cleanup.lnk
Target : C:\Windows\system32\cleanmgr.exe
Version : 10.0.14393.0

- Event Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Event Viewer.lnk
Target : C:\Windows\system32\eventvwr.msc
Version : unknown

- IIS Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\IIS Manager.lnk
Target : C:\Windows\system32\inetsrv\InetMgr.exe
Version : 10.0.14393.0

- iSCSI Initiator.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\iSCSI Initiator.lnk
Target : C:\Windows\system32\iscsicpl.exe
Version : 10.0.14393.0

- Memory Diagnostics Tool.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Memory Diagnostics Tool.lnk
Target : C:\Windows\system32\MdSched.exe
Version : 10.0.14393.0

- Microsoft Azure services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Microsoft Azure services.lnk
Target : C:\Windows\explorer.exe
Version : 10.0.14393.2273

- ODBC Data Sources (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (32-bit).lnk
Target : C:\Windows\syswow64\odbcad32.exe
Version : 10.0.14393.0

- ODBC Data Sources (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\ODBC Data Sources (64-bit).lnk
Target : C:\Windows\system32\odbcad32.exe
Version : 10.0.14393.0

- Performance Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Performance Monitor.lnk
Target : C:\Windows\system32\perfmon.msc
Version : unknown

- Print Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Print Management.lnk
Target : C:\Windows\system32\printmanagement.msc
Version : unknown

- Resource Monitor.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Resource Monitor.lnk
Target : C:\Windows\system32\perfmon.exe
Version : 10.0.14393.0

- Security Configuration Management.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Security Configuration Management.lnk
Target : C:\Windows\system32\secpol.msc
Version : unknown

- Server Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Server Manager.lnk
Target : C:\Windows\system32\ServerManager.exe
Version : 10.0.14393.2156

- services.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\services.lnk
Target : C:\Windows\system32\services.msc
Version : unknown

- System Configuration.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Configuration.lnk
Target : C:\Windows\system32\msconfig.exe
Version : 1.0.0.1

- System Information.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\System Information.lnk
Target : C:\Windows\system32\msinfo32.exe
Version : 10.0.14393.1480

- Task Scheduler.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Task Scheduler.lnk
Target : C:\Windows\system32\taskschd.msc
Version : unknown

- Windows Firewall with Advanced Security.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Firewall with Advanced Security.lnk
Target : C:\Windows\system32\WF.msc
Version : unknown

- Windows Server Backup.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Administrative Tools\Windows Server Backup.lnk
Target : C:\Windows\system32\wbadmin.msc
Version : unknown

- HP Array Configuration Utility (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\HP System Tools\HP Array Configuration Utility (64-bit)\HP Array Configuration Utility (64-bit).lnk
Target : C:\Program Files\Compaq\Cpqacuxe\Bin\cpqacuxe.exe
Version : 9.10.22.0

- README.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\HP System Tools\HP Array Configuration Utility (64-bit)\README.lnk
Target : C:\Program Files\Compaq\Cpqacuxe\README.TXT
Version : unknown

- Setup HP Array Configuration Utility.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\HP System Tools\HP Array Configuration Utility (64-bit)\Setup HP Array Configuration Utility.lnk
Target : C:\Program Files\Compaq\Cpqacuxe\Bin\cpqacuxe.exe
Version : 9.10.22.0

- About Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\About Java.lnk
Target : C:\Program Files\Java\jre-1.8\bin\javacpl.exe
Version : 11.401.2.10

- Check For Updates.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Check For Updates.lnk
Target : C:\Program Files\Java\jre-1.8\bin\javacpl.exe
Version : 11.401.2.10

- Configure Java.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Java\Configure Java.lnk
Target : C:\Program Files\Java\jre-1.8\bin\javacpl.exe
Version : 11.401.2.10

- Kaspersky Endpoint Security for Windows.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Kaspersky Endpoint Security for Windows\Kaspersky Endpoint Security for Windows.lnk
Target : C:\Program Files (x86)\Kaspersky Lab\KES.12.3.0\avpui.exe
Version : 21.15.8.493

- Microsoft Excel 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Excel 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\xlicons.exe
Version : 14.0.6009.1000

- Microsoft OneNote 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft OneNote 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\joticon.exe
Version : 14.0.6009.1000

- Microsoft Outlook 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Outlook 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\outicon.exe
Version : 14.0.6009.1000

- Microsoft PowerPoint 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft PowerPoint 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\pptico.exe
Version : 14.0.6009.1000

- Microsoft Publisher 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Publisher 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\pubs.exe
Version : 14.0.6009.1000

- Microsoft Word 2010.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Word 2010.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\wordicon.exe
Version : 14.0.6009.1000

- Digital Certificate for VBA Projects.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Digital Certificate for VBA Projects.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.6009.1000

- Microsoft Clip Organizer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Clip Organizer.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\cagicon.exe
Version : 14.0.6009.1000

- Microsoft Office 2010 Language Preferences.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Language Preferences.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\misc.exe
Version : 14.0.6009.1000

- Microsoft Office 2010 Upload Center.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\msouc.exe
Version : 14.0.6009.1000

- Microsoft Office Picture Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office Picture Manager.lnk
Target : C:\Windows\Installer\{90140000-0012-0000-0000-0000000FF1CE}\oisicon.exe
Version : 14.0.6009.1000

- SQL Server Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2008\Configuration Tools\SQL Server Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x64\LandingPage.exe
Version : 10.0.5500.0

- SQL Server 2016 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2016\SQL Server 2016 Import and Export Data (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\130\DTS\Binn\DTSWizard.exe
Version : 13.0.5026.0

- SQL Server 2016 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2016\Configuration Tools\SQL Server 2016 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.14393.2097

- SQL Server 2016 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2016\Configuration Tools\SQL Server 2016 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\130\Shared\SqlWtsn.exe
Version : 13.0.1601.5

- SQL Server 2016 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2016\Configuration Tools\SQL Server 2016 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\130\Setup Bootstrap\SQLServer2016\x64\LandingPage.exe
Version : 13.0.5026.0

- SQL Server 2019 Import and Export Data (32-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (32-bit).lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.2000.5

- SQL Server 2019 Import and Export Data (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\SQL Server 2019 Import and Export Data (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\DTS\Binn\DTSWizard.exe
Version : 15.0.2000.5

- SQL Server 2019 Configuration Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Configuration Manager.lnk
Target : C:\Windows\SysWOW64\mmc.exe
Version : 10.0.14393.2097

- SQL Server 2019 Error and Usage Reporting.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Error and Usage Reporting.lnk
Target : C:\Program Files\Microsoft SQL Server\150\Shared\SqlWtsn.exe
Version : 15.0.2000.5

- SQL Server 2019 Installation Center (64-bit).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Configuration Tools\SQL Server 2019 Installation Center (64-bit).lnk
Target : C:\Program Files\Microsoft SQL Server\150\Setup Bootstrap\SQL2019\x64\LandingPage.exe
Version : 15.0.2000.5

- SQL Server 2019 Data Quality Client.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Client.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn\DQ\DataQualityServices.exe
Version : 15.0.2000.5

- SQL Server 2019 Data Quality Server Installer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server 2019\Data Quality Services\SQL Server 2019 Data Quality Server Installer.lnk
Target : C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\DQSInstaller.exe
Version : 15.0.2000.5

- Analysis Services Deployment Wizard 20.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 20\Analysis Services Deployment Wizard 20.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\IDE\Microsoft.AnalysisServices.Deployment.exe
Version : 20.0.3.0

- SQL Server Management Studio 20.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 20\SQL Server Management Studio 20.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\IDE\Ssms.exe
Version : 20.1.10.0

- Database Engine Tuning Advisor 20.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 20\Performance Tools\Database Engine Tuning Advisor 20.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\DTASHELL.EXE
Version : 20.1.10.0

- SQL Server Profiler 20.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\Microsoft SQL Server Tools 20\Performance Tools\SQL Server Profiler 20.lnk
Target : C:\Program Files (x86)\Microsoft SQL Server Management Studio 20\Common7\PROFILER.EXE
Version : 2022.160.4108.0

- VNC Address Book.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Address Book.lnk
Target : C:\Program Files\RealVNC\VNC4\vncaddrbook.exe
Version : 4.6.1.54321

- VNC Server.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Server.lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- Enter VNC Server License Key.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Enter VNC Server License Key.lnk
Target : C:\Program Files\RealVNC\VNC4\vncconfig.exe
Version : 4.6.1.54321

- Start Listening VNC Viewer.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\Start Listening VNC Viewer.lnk
Target : C:\Program Files\RealVNC\VNC4\vncviewer.exe
Version : 4.6.1.54321

- VNC Server (User Mode).lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\RealVNC\Advanced\VNC Server (User Mode).lnk
Target : C:\Program Files\RealVNC\VNC4\winvnc4.exe
Version : 4.6.1.54321

- Task Manager.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\System Tools\Task Manager.lnk
Target : C:\Windows\system32\taskmgr.exe
Version : 1.0.0.1

- Console RAR manual.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\Console RAR manual.lnk
Target : C:\Program Files\WinRAR\Rar.txt
Version : unknown

- What is new in the latest version.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\What is new in the latest version.lnk
Target : C:\Program Files\WinRAR\WhatsNew.txt
Version : unknown

- WinRAR help.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR help.lnk
Target : C:\Program Files\WinRAR\WinRAR.chm
Version : unknown

- WinRAR.lnk
.lnk Path : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\WinRAR\WinRAR.lnk
Target : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0
58452 - Microsoft Windows Startup Software Enumeration
-
Synopsis
It is possible to enumerate startup software.
Description
This plugin lists software that is configured to run on system startup by crawling the registry entries in :

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersi on\Run
Solution
Review the list of applications and remove any that are not compliant with your organization's acceptable use and security policies.
Risk Factor
None
Plugin Information
Published: 2012/03/23, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


The following startup item was found :

SunJavaUpdateSched - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
38153 - Microsoft Windows Summary of Missing Patches
-
Synopsis
The remote host is missing several Microsoft security patches.
Description
This plugin summarizes updates for Microsoft Security Bulletins or Knowledge Base (KB) security updates that have not been installed on the remote Windows host based on the results of either a credentialed check using the supplied credentials or a check done using a supported third-party patch management tool.

Note the results of missing patches also include superseded patches.

Review the summary and apply any missing updates in order to be up to date.
Solution
Run Windows Update on the remote host or use a patch management solution.
Risk Factor
None
Plugin Information
Published: 2009/04/24, Modified: 2019/06/13
Plugin Output

tcp/445/cifs

The patches for the following bulletins or KBs are missing on the remote host :

- MS11-072 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-072 )
- MS11-073 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-073 )
- MS11-089 ( http://technet.microsoft.com/en-us/security/bulletin/ms11-089 )
- MS12-027 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-027 )
- MS12-030 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-030 )
- MS12-057 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-057 )
- MS12-060 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-060 )
- MS12-064 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-064 )
- MS12-076 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-076 )
- MS12-079 ( http://technet.microsoft.com/en-us/security/bulletin/ms12-079 )
- MS13-042 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-042 )
- MS13-068 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-068 )
- MS13-072 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-072 )
- MS13-073 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-073 )
- MS13-074 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-074 )
- MS13-085 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-085 )
- MS13-094 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-094 )
- MS13-106 ( http://technet.microsoft.com/en-us/security/bulletin/ms13-106 )
- MS14-001 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-001 )
- MS14-017 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-017 )
- MS14-024 ( http://technet.microsoft.com/en-us/security/bulletin/ms14-024 )
- KB4015217 ( https://support.microsoft.com/en-us/help/4015217 )
- KB4019472 ( https://support.microsoft.com/en-us/help/4019472 )
- KB2956078 ( https://support.microsoft.com/en-us/help/2956078 )
- KB4011089 ( https://support.microsoft.com/en-us/help/4011089 )
- KB4038782 ( https://support.microsoft.com/en-us/help/4038782 )
- KB4011196 ( https://support.microsoft.com/en-us/help/4011196 )
- KB4011273 ( https://support.microsoft.com/en-us/help/4011273 )
- KB4011711 ( https://support.microsoft.com/en-us/help/4011711 )
- KB4103723 ( https://support.microsoft.com/en-us/help/4103723 )
- KB4022205 ( https://support.microsoft.com/en-us/help/4022205 )
- KB4284880 ( https://support.microsoft.com/en-us/help/4284880 )
- KB4338814 ( https://support.microsoft.com/en-us/help/4338814 )
- KB4032222 ( https://support.microsoft.com/en-us/help/4032222 )
- KB4343887 ( https://support.microsoft.com/en-us/help/4343887 )
- KB4346087 ( https://support.microsoft.com/en-us/help/4346087 )
- KB4091664 ( https://support.microsoft.com/en-us/help/4091664 )
- KB4457131 ( https://support.microsoft.com/en-us/help/4457131 )
- KB4227170 ( https://support.microsoft.com/en-us/help/4227170 )
- KB4462917 ( https://support.microsoft.com/en-us/help/4462917 )
- KB4461529 ( https://support.microsoft.com/en-us/help/4461529 )
- KB4467691 ( https://support.microsoft.com/en-us/help/4467691 )
- KB4461576 ( https://support.microsoft.com/en-us/help/4461576 )
- KB4471321 ( https://support.microsoft.com/en-us/help/4471321 )
- KB4483229 ( https://support.microsoft.com/en-us/help/4483229 )
- KB4091664 ( https://support.microsoft.com/en-us/help/4091664 )
- KB4461623 ( https://support.microsoft.com/en-us/help/4461623 )
- KB4480961 ( https://support.microsoft.com/en-us/help/4480961 )
- KB4487026 ( https://support.microsoft.com/en-us/help/4487026 )
- KB4489882 ( https://support.microsoft.com/en-us/help/4489882 )
- KB4493470 ( https://support.microsoft.com/en-us/help/4493470 )
- KB4494440 ( https://support.microsoft.com/en-us/help/4494440 )
- KB4503267 ( https://support.microsoft.com/en-us/help/4503267 )
- KB4507460 ( https://support.microsoft.com/en-us/help/4507460 )
- KB4512517 ( https://support.microsoft.com/en-us/help/4512517 )
- KB4516044 ( https://support.microsoft.com/en-us/help/4516044 )
- KB4519998 ( https://support.microsoft.com/en-us/help/4519998 )
- KB4525236 ( https://support.microsoft.com/en-us/help/4525236 )
- KB4530689 ( https://support.microsoft.com/en-us/help/4530689 )
- KB4534271 ( https://support.microsoft.com/en-us/help/4534271 )
- KB4537764 ( https://support.microsoft.com/en-us/help/4537764 )
- KB4540670 ( https://support.microsoft.com/en-us/help/4540670 )
- KB4550929 ( https://support.microsoft.com/en-us/help/4550929 )
- KB4556813 ( https://support.microsoft.com/en-us/help/4556813 )
- KB4561616 ( https://support.microsoft.com/en-us/help/4561616 )
- KB4565511 ( https://support.microsoft.com/en-us/help/4565511 )
- KB4571694 ( https://support.microsoft.com/en-us/help/4571694 )
- KB4577015 ( https://support.microsoft.com/en-us/help/4577015 )
- KB4571694 ( https://support.microsoft.com/en-us/help/4571694 )
- KB4580346 ( https://support.microsoft.com/en-us/help/4580346 )
- KB4586830 ( https://support.microsoft.com/en-us/help/4586830 )
- KB4593226 ( https://support.microsoft.com/en-us/help/4593226 )
- KB4598243 ( https://support.microsoft.com/en-us/help/4598243 )
- KB4601318 ( https://support.microsoft.com/en-us/help/4601318 )
- KB5000803 ( https://support.microsoft.com/en-us/help/5000803 )
- KB5001347 ( https://support.microsoft.com/en-us/help/5001347 )
- KB5003197 ( https://support.microsoft.com/en-us/help/5003197 )
- KB5003638 ( https://support.microsoft.com/en-us/help/5003638 )
- KB5004238 ( https://support.microsoft.com/en-us/help/5004238 )
- KB5004948 ( https://support.microsoft.com/en-us/help/5004948 )
- KB5005043 ( https://support.microsoft.com/en-us/help/5005043 )
- KB5005573 ( https://support.microsoft.com/en-us/help/5005573 )
- KB5006669 ( https://support.microsoft.com/en-us/help/5006669 )
- KB5007192 ( https://support.microsoft.com/en-us/help/5007192 )
- KB5008207 ( https://support.microsoft.com/en-us/help/5008207 )
- KB5009546 ( https://support.microsoft.com/en-us/help/5009546 )
- KB5010359 ( https://support.microsoft.com/en-us/help/5010359 )
- KB5011495 ( https://support.microsoft.com/en-us/help/5011495 )
- KB5012596 ( https://support.microsoft.com/en-us/help/5012596 )
- KB5013952 ( https://support.microsoft.com/en-us/help/5013952 )
- KB5014702 ( https://support.microsoft.com/en-us/help/5014702 )
- KB5015808 ( https://support.microsoft.com/en-us/help/5015808 )
- KB5016622 ( https://support.microsoft.com/en-us/help/5016622 )
- KB5017305 ( https://support.microsoft.com/en-us/help/5017305 )
- KB5018411 ( https://support.microsoft.com/en-us/help/5018411 )
- KB5019964 ( https://support.microsoft.com/en-us/help/5019964 )
- KB5021235 ( https://support.microsoft.com/en-us/help/5021235 )
- KB5022289 ( https://support.microsoft.com/en-us/help/5022289 )
- KB5022838 ( https://support.microsoft.com/en-us/help/5022838 )
- KB5023697 ( https://support.microsoft.com/en-us/help/5023697 )
- KB5025228 ( https://support.microsoft.com/en-us/help/5025228 )
- KB5026363 ( https://support.microsoft.com/en-us/help/5026363 )
- KB5027219 ( https://support.microsoft.com/en-us/help/5027219 )
- KB5028169 ( https://support.microsoft.com/en-us/help/5028169 )
- KB5029242 ( https://support.microsoft.com/en-us/help/5029242 )
- KB5030213 ( https://support.microsoft.com/en-us/help/5030213 )
- KB5031362 ( https://support.microsoft.com/en-us/help/5031362 )
- KB5032197 ( https://support.microsoft.com/en-us/help/5032197 )
- KB5033373 ( https://support.microsoft.com/en-us/help/5033373 )
- KB5034119 ( https://support.microsoft.com/en-us/help/5034119 )
- KB5034767 ( https://support.microsoft.com/en-us/help/5034767 )
- KB5035855 ( https://support.microsoft.com/en-us/help/5035855 )
- KB5036899 ( https://support.microsoft.com/en-us/help/5036899 )
- KB5037763 ( https://support.microsoft.com/en-us/help/5037763 )
- KB5039214 ( https://support.microsoft.com/en-us/help/5039214 )
- KB5040434 ( https://support.microsoft.com/en-us/help/5040434 )
- KB5041773 ( https://support.microsoft.com/en-us/help/5041773 )
- KB5043051 ( https://support.microsoft.com/en-us/help/5043051 )
- KB5044293 ( https://support.microsoft.com/en-us/help/5044293 )
- KB5046612 ( https://support.microsoft.com/en-us/help/5046612 )
- KB5048671 ( https://support.microsoft.com/en-us/help/5048671 )
- KB5049993 ( https://support.microsoft.com/en-us/help/5049993 )
- KB5052006 ( https://support.microsoft.com/en-us/help/5052006 )
- KB5053594 ( https://support.microsoft.com/en-us/help/5053594 )
- KB5055521 ( https://support.microsoft.com/en-us/help/5055521 )
- KB5058383 ( https://support.microsoft.com/en-us/help/5058383 )
- KB5061010 ( https://support.microsoft.com/en-us/help/5061010 )
- KB5062560 ( https://support.microsoft.com/en-us/help/5062560 )
- KB5063871 ( https://support.microsoft.com/en-us/help/5063871 )
- KB5065427 ( https://support.microsoft.com/en-us/help/5065427 )
- KB5066836 ( https://support.microsoft.com/en-us/help/5066836 )
- KB5068864 ( https://support.microsoft.com/en-us/help/5068864 )
- KB5071543 ( https://support.microsoft.com/en-us/help/5071543 )

92369 - Microsoft Windows Time Zone Information
-
Synopsis
Nessus was able to collect and report time zone information from the remote host.
Description
Nessus was able to collect time zone information from the remote Windows host and generate a report as a CSV attachment.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2023/06/06
Plugin Output

tcp/0

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\TimeZoneKeyName : India Standard Time
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardName : @tzres.dll,-492
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightName : @tzres.dll,-491
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DynamicDaylightTimeDisabled : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardBias : 0x00000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightBias : 0xFFFFFFC4
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\Bias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\ActiveTimeBias : 0xFFFFFEB6
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\DaylightStart : 00000000000000000000000000000000
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\StandardStart : 00000000000000000000000000000000
19506 - Nessus Scan Information
-
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :

- The version of the plugin set.
- The type of scanner (Nessus or Nessus Home).
- The version of the Nessus Engine.
- The port scanner(s) used.
- The port range scanned.
- The ping round trip time
- Whether credentialed or third-party patch management checks are possible.
- Whether the display of superseded patches is enabled
- The date of the scan.
- The duration of the scan.
- The number of hosts scanned in parallel.
- The number of checks done in parallel.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2025/10/29
Plugin Output

tcp/0

Information about this scan :

Nessus version : 10.11.1
Nessus build : 20021
Plugin feed version : 202601041845
Scanner edition used : Nessus
Scanner OS : WINDOWS
Scanner distribution : win-x86-64
Scan type : Normal
Scan name : Server 1
Scan policy used : Server
Scanner IP : 172.17.100.38
Port scanner(s) : wmi_netstat
Port range : 1-65535
Ping RTT : Unavailable
Thorough tests : no
Experimental tests : no
Scan for Unpatched Vulnerabilities : yes
Plugin debugging enabled : yes (at debugging level 4)
Paranoia level : 0
Report verbosity : 2
Safe checks : yes
Optimize the test : yes
Credentialed checks : yes, as '172.17.100.73\tidua' via SMB
Patch management checks : None
Display superseded patches : yes (supersedence plugin did not launch)
CGI scanning : disabled
Web application tests : disabled
Max hosts : 2
Max checks : 2
Recv timeout : 5
Backports : None
Allow post-scan editing : Yes
Nessus Plugin Signature Checking : Enabled
Audit File Signature Checking : Disabled
Scan Start Date : 2026/1/10 5:02 India Standard Time (UTC +05:30)
Scan duration : 2342 sec
Scan for malware : no

43815 - NetBIOS Multiple IP Address Enumeration
-
Synopsis
The remote host is configured with multiple IP addresses.
Description
By sending a special NetBIOS query, Nessus was able to detect the use of multiple IP addresses on the remote host. This indicates the host may be running virtualization software, a VPN client, or has multiple network interfaces.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/01/06, Modified: 2011/09/02
Plugin Output

udp/137/netbios-ns


The remote host appears to be using the following IP addresses :

- 10.113.99.73
- 172.17.100.73
- 10.20.30.61
- 10.195.58.173

58651 - Netstat Active Connections
-
Synopsis
Active connections are enumerated via the 'netstat' command.
Description
This plugin runs 'netstat' on the remote machine to enumerate all active 'ESTABLISHED' or 'LISTENING' tcp/udp connections.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/04/10, Modified: 2021/06/29
Plugin Output

tcp/0


Netstat output :

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 764
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:1433 0.0.0.0:0 LISTENING 2928
TCP 0.0.0.0:2383 0.0.0.0:0 LISTENING 4352
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1060
TCP 0.0.0.0:5053 0.0.0.0:0 LISTENING 13868
TCP 0.0.0.0:5059 0.0.0.0:0 LISTENING 15924
TCP 0.0.0.0:5800 0.0.0.0:0 LISTENING 3472
TCP 0.0.0.0:5900 0.0.0.0:0 LISTENING 3472
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:25002 0.0.0.0:0 LISTENING 7352
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 832
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 1180
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1052
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 2304
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2212
TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING 912
TCP 0.0.0.0:49672 0.0.0.0:0 LISTENING 920
TCP 0.0.0.0:51528 0.0.0.0:0 LISTENING 16056
TCP 0.0.0.0:51529 0.0.0.0:0 LISTENING 16056
TCP 10.20.30.61:139 0.0.0.0:0 LISTENING 4
TCP 10.113.99.73:139 0.0.0.0:0 LISTENING 4
TCP 10.195.58.173:139 0.0.0.0:0 LISTENING 4
TCP 127.0.0.1:1434 0.0.0.0:0 LISTENING 2928
TCP 127.0.0.1:1550 0.0.0.0:0 LISTENING 7828
TCP 127.0.0.1:1551 0.0.0.0:0 LISTENING 7828
TCP 127.0.0.1:5059 127.0.0.1:49688 ESTABLISHED 15924
TCP 127.0.0.1:8015 0.0.0.0:0 LISTENING 16056
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING 7828
TCP 127.0.0.1:49669 0.0.0.0:0 LISTENING 2928
TCP 127.0.0.1:49671 0.0.0.0:0 LISTENING 2480
TCP 127.0.0.1:49684 127.0.0.1:49685 ESTABLISHED 8084
TCP 127.0.0.1:49685 127.0.0.1:49684 ESTABLISHED 8084
TCP 127.0.0.1:49686 0.0.0.0:0 LISTENING 7828
TCP 127.0.0.1:49688 127.0.0.1:5059 ESTABLISHED 8024
TCP 127.0.0.1:54736 127.0.0.1:54737 ESTABLISHED 16056
TCP 127.0.0.1:54737 127.0.0.1:54736 ESTABLISHED 16056
TCP 127.0.0.1:54738 127.0.0.1:54739 ESTABLISHED 16056
TCP 127.0.0.1:54739 127.0.0.1:54738 ESTABLISHED 16056
TCP 127.0.0.1:56066 127.0.0.1:56067 ESTABLISHED 7352
TCP 127.0.0.1:56067 127.0.0.1:56066 ESTABLISHED 7352
TCP 127.0.0.1:56068 127.0.0.1:56069 ESTABLISHED 7352
TCP 127.0.0.1:56069 127.0.0.1:56068 ESTABLISHED 7352
TCP 127.0.0.1:56070 127.0.0.1:56071 ESTABLISHED 7352
TCP 127.0.0.1:56071 127.0.0.1:56070 ESTABLISHED 7352
TCP 127.0.0.1:56072 127.0.0.1:56073 ESTABLISHED 7352
TCP 127.0.0.1:56073 127.0.0.1:56072 ESTABLISHED 7352
TCP 127.0.0.1:56074 127.0.0.1:56075 ESTABLISHED 7352
TCP 127.0.0.1:56075 127.0.0.1:56074 ESTABLISHED 7352
TCP 127.0.0.1:56076 127.0.0.1:56077 ESTABLISHED 7352
TCP 127.0.0.1:56077 127.0.0.1:56076 ESTABLISHED 7352
TCP 127.0.0.1:56078 127.0.0.1:56079 ESTABLISHED 7352
TCP 127.0.0.1:56079 127.0.0.1:56078 ESTABLISHED 7352
TCP 127.0.0.1:56080 127.0.0.1:56081 ESTABLISHED 7352
TCP 127.0.0.1:56081 127.0.0.1:56080 ESTABLISHED 7352
TCP 127.0.0.1:56082 127.0.0.1:56083 ESTABLISHED 7352
TCP 127.0.0.1:56083 127.0.0.1:56082 ESTABLISHED 7352
TCP 127.0.0.1:56084 127.0.0.1:56085 ESTABLISHED 7352
TCP 127.0.0.1:56085 127.0.0.1:56084 ESTABLISHED 7352
TCP 127.0.0.1:56086 127.0.0.1:56087 ESTABLISHED 7352
TCP 127.0.0.1:56087 127.0.0.1:56086 ESTABLISHED 7352
TCP 127.0.0.1:56088 127.0.0.1:56089 ESTABLISHED 7352
TCP 127.0.0.1:56089 127.0.0.1:56088 ESTABLISHED 7352
TCP 127.0.0.1:56090 127.0.0.1:56091 ESTABLISHED 7352
TCP 127.0.0.1:56091 127.0.0.1:56090 ESTABLISHED 7352
TCP 127.0.0.1:56092 127.0.0.1:56093 ESTABLISHED 7352
TCP 127.0.0.1:56093 127.0.0.1:56092 ESTABLISHED 7352
TCP 127.0.0.1:56094 127.0.0.1:56095 ESTABLISHED 7352
TCP 127.0.0.1:56095 127.0.0.1:56094 ESTABLISHED 7352
TCP 127.0.0.1:56096 127.0.0.1:56097 ESTABLISHED 7352
TCP 127.0.0.1:56097 127.0.0.1:56096 ESTABLISHED 7352
TCP 127.0.0.1:56098 127.0.0.1:56099 ESTABLISHED 7352
TCP 127.0.0.1:56099 127.0.0.1:56098 ESTABLISHED 7352
TCP 172.17.100.73:135 172.17.100.38:51684 ESTABLISHED 764
TCP 172.17.100.73:139 0.0.0.0:0 LISTENING 4
TCP 172.17.100.73:445 172.17.100.38:51683 ESTABLISHED 4
TCP 172.17.100.73:1433 172.17.100.73:61825 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61826 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61827 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61828 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61833 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61834 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61835 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61836 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61837 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61838 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61839 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61840 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61842 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61843 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61844 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61845 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61850 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61851 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61853 ESTABLISHED 2928
TCP 172.17.100.73:1433 172.17.100.73:61854 ESTABLISHED 2928
TCP 172.17.100.73:3389 172.17.100.254:14636 ESTABLISHED 1060
TCP 172.17.100.73:5059 172.17.100.254:2714 ESTABLISHED 15924
TCP 172.17.100.73:25002 172.17.100.73:49710 ESTABLISHED 7352
TCP 172.17.100.73:25002 172.17.100.88:50443 ESTABLISHED 7352
TCP 172.17.100.73:25002 172.17.100.254:19788 ESTABLISHED 7352
TCP 172.17.100.73:25002 172.17.100.254:36160 ESTABLISHED 7352
TCP 172.17.100.73:25002 172.17.100.254:55858 ESTABLISHED 7352
TCP 172.17.100.73:49666 172.17.100.38:51685 ESTABLISHED 1052
TCP 172.17.100.73:49710 172.17.100.73:25002 ESTABLISHED 8024
TCP 172.17.100.73:49729 172.17.100.187:445 ESTABLISHED 4
TCP 172.17.100.73:49732 172.17.100.184:445 ESTABLISHED 4
TCP 172.17.100.73:49733 172.17.100.222:445 ESTABLISHED 4
TCP 172.17.100.73:52188 4.213.25.241:443 ESTABLISHED 9204
TCP 172.17.100.73:54176 192.168.10.80:445 ESTABLISHED 4
TCP 172.17.100.73:61346 172.17.100.91:445 ESTABLISHED 4
TCP 172.17.100.73:61825 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61826 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61827 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61828 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61833 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61834 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61835 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61836 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61837 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61838 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61839 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61840 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61842 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61843 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61844 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61845 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61850 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61851 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61853 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61854 172.17.100.73:1433 ESTABLISHED 7352
TCP 172.17.100.73:61869 4.213.25.240:443 ESTABLISHED 1052
TCP 172.17.100.73:61897 20.189.173.15:443 ESTABLISHED 2392
TCP 172.17.100.73:65277 172.17.100.51:445 ESTABLISHED 4
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 764
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:1433 [::]:0 LISTENING 2928
TCP [::]:2383 [::]:0 LISTENING 4352
TCP [::]:3389 [::]:0 LISTENING 1060
TCP [::]:5800 [::]:0 LISTENING 3472
TCP [::]:5900 [::]:0 LISTENING 3472
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:25002 [::]:0 LISTENING 7352
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 832
TCP [::]:49665 [::]:0 LISTENING 1180
TCP [::]:49666 [::]:0 LISTENING 1052
TCP [::]:49667 [::]:0 LISTENING 2304
TCP [::]:49668 [::]:0 LISTENING 2212
TCP [::]:49670 [::]:0 LISTENING 912
TCP [::]:49672 [::]:0 LISTENING 920
TCP [::]:51528 [::]:0 LISTENING 16056
TCP [::]:51529 [::]:0 LISTENING 16056
TCP [::1]:1434 [::]:0 LISTENING 2928
TCP [::1]:1550 [::]:0 LISTENING 7828
TCP [::1]:1551 [::]:0 LISTENING 7828
TCP [::1]:30523 [::]:0 LISTENING 7828
TCP [::1]:49669 [::]:0 LISTENING 2928
TCP [::1]:49686 [::]:0 LISTENING 7828
UDP 0.0.0.0:500 *:* 1052
UDP 0.0.0.0:1434 *:* 2668
UDP 0.0.0.0:3389 *:* 1060
UDP 0.0.0.0:4500 *:* 1052
UDP 0.0.0.0:5050 *:* 1428
UDP 0.0.0.0:5353 *:* 1728
UDP 0.0.0.0:5355 *:* 1728
UDP 0.0.0.0:15000 *:* 7828
UDP 0.0.0.0:15902 *:* 7352
UDP 0.0.0.0:18901 *:* 7352
UDP 0.0.0.0:19096 *:* 7352
UDP 0.0.0.0:28446 *:* 7352
UDP 0.0.0.0:28702 *:* 7352
UDP 0.0.0.0:28958 *:* 7352
UDP 0.0.0.0:51422 *:* 8084
UDP 10.20.30.61:137 *:* 4
UDP 10.20.30.61:138 *:* 4
UDP 10.20.30.61:1900 *:* 7264
UDP 10.20.30.61:54434 *:* 7264
UDP 10.113.99.73:137 *:* 4
UDP 10.113.99.73:138 *:* 4
UDP 10.113.99.73:1900 *:* 7264
UDP 10.113.99.73:54435 *:* 7264
UDP 10.195.58.173:137 *:* 4
UDP 10.195.58.173:138 *:* 4
UDP 10.195.58.173:1900 *:* 7264
UDP 10.195.58.173:54437 *:* 7264
UDP 127.0.0.1:1900 *:* 7264
UDP 127.0.0.1:54438 *:* 7264
UDP 127.0.0.1:61278 *:* 1052
UDP 172.17.100.73:137 *:* 4
UDP 172.17.100.73:138 *:* 4
UDP 172.17.100.73:1900 *:* 7264
UDP 172.17.100.73:54436 *:* 7264
UDP [::]:500 *:* 1052
UDP [::]:1434 *:* 2668
UDP [::]:3389 *:* 1060
UDP [::]:4500 *:* 1052
UDP [::]:15000 *:* 7828
UDP [::]:15902 *:* 7352
UDP [::]:18901 *:* 7352
UDP [::]:19096 *:* 7352
UDP [::]:28446 *:* 7352
UDP [::]:28702 *:* 7352
UDP [::]:28958 *:* 7352
UDP [::1]:1900 *:* 7264
UDP [::1]:54433 *:* 7264
64582 - Netstat Connection Information
-
Synopsis
Nessus was able to parse the results of the 'netstat' command on the remote host.
Description
The remote host has listening ports or established connections that Nessus was able to extract from the results of the 'netstat' command.

Note: The output for this plugin can be very long, and is not shown by default. To display it, enable verbose reporting in scan settings.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/13, Modified: 2023/05/23
Plugin Output

tcp/0

tcp4 (listen)
src: [host=0.0.0.0, port=80]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=135]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=445]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=1433]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=2383]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5053]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5059]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5800]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5900]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=5985]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=25002]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=47001]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49664]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49665]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49666]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49667]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49668]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49670]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=49672]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=51528]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=0.0.0.0, port=51529]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=10.20.30.61, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=10.113.99.73, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=10.195.58.173, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1434]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1550]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=1551]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=5059]
dst: [host=127.0.0.1, port=49688]

tcp4 (listen)
src: [host=127.0.0.1, port=8015]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=30523]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49669]
dst: [host=0.0.0.0, port=0]

tcp4 (listen)
src: [host=127.0.0.1, port=49671]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49684]
dst: [host=127.0.0.1, port=49685]

tcp4 (established)
src: [host=127.0.0.1, port=49685]
dst: [host=127.0.0.1, port=49684]

tcp4 (listen)
src: [host=127.0.0.1, port=49686]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=127.0.0.1, port=49688]
dst: [host=127.0.0.1, port=5059]

tcp4 (established)
src: [host=127.0.0.1, port=54736]
dst: [host=127.0.0.1, port=54737]

tcp4 (established)
src: [host=127.0.0.1, port=54737]
dst: [host=127.0.0.1, port=54736]

tcp4 (established)
src: [host=127.0.0.1, port=54738]
dst: [host=127.0.0.1, port=54739]

tcp4 (established)
src: [host=127.0.0.1, port=54739]
dst: [host=127.0.0.1, port=54738]

tcp4 (established)
src: [host=127.0.0.1, port=56066]
dst: [host=127.0.0.1, port=56067]

tcp4 (established)
src: [host=127.0.0.1, port=56067]
dst: [host=127.0.0.1, port=56066]

tcp4 (established)
src: [host=127.0.0.1, port=56068]
dst: [host=127.0.0.1, port=56069]

tcp4 (established)
src: [host=127.0.0.1, port=56069]
dst: [host=127.0.0.1, port=56068]

tcp4 (established)
src: [host=127.0.0.1, port=56070]
dst: [host=127.0.0.1, port=56071]

tcp4 (established)
src: [host=127.0.0.1, port=56071]
dst: [host=127.0.0.1, port=56070]

tcp4 (established)
src: [host=127.0.0.1, port=56072]
dst: [host=127.0.0.1, port=56073]

tcp4 (established)
src: [host=127.0.0.1, port=56073]
dst: [host=127.0.0.1, port=56072]

tcp4 (established)
src: [host=127.0.0.1, port=56074]
dst: [host=127.0.0.1, port=56075]

tcp4 (established)
src: [host=127.0.0.1, port=56075]
dst: [host=127.0.0.1, port=56074]

tcp4 (established)
src: [host=127.0.0.1, port=56076]
dst: [host=127.0.0.1, port=56077]

tcp4 (established)
src: [host=127.0.0.1, port=56077]
dst: [host=127.0.0.1, port=56076]

tcp4 (established)
src: [host=127.0.0.1, port=56078]
dst: [host=127.0.0.1, port=56079]

tcp4 (established)
src: [host=127.0.0.1, port=56079]
dst: [host=127.0.0.1, port=56078]

tcp4 (established)
src: [host=127.0.0.1, port=56080]
dst: [host=127.0.0.1, port=56081]

tcp4 (established)
src: [host=127.0.0.1, port=56081]
dst: [host=127.0.0.1, port=56080]

tcp4 (established)
src: [host=127.0.0.1, port=56082]
dst: [host=127.0.0.1, port=56083]

tcp4 (established)
src: [host=127.0.0.1, port=56083]
dst: [host=127.0.0.1, port=56082]

tcp4 (established)
src: [host=127.0.0.1, port=56084]
dst: [host=127.0.0.1, port=56085]

tcp4 (established)
src: [host=127.0.0.1, port=56085]
dst: [host=127.0.0.1, port=56084]

tcp4 (established)
src: [host=127.0.0.1, port=56086]
dst: [host=127.0.0.1, port=56087]

tcp4 (established)
src: [host=127.0.0.1, port=56087]
dst: [host=127.0.0.1, port=56086]

tcp4 (established)
src: [host=127.0.0.1, port=56088]
dst: [host=127.0.0.1, port=56089]

tcp4 (established)
src: [host=127.0.0.1, port=56089]
dst: [host=127.0.0.1, port=56088]

tcp4 (established)
src: [host=127.0.0.1, port=56090]
dst: [host=127.0.0.1, port=56091]

tcp4 (established)
src: [host=127.0.0.1, port=56091]
dst: [host=127.0.0.1, port=56090]

tcp4 (established)
src: [host=127.0.0.1, port=56092]
dst: [host=127.0.0.1, port=56093]

tcp4 (established)
src: [host=127.0.0.1, port=56093]
dst: [host=127.0.0.1, port=56092]

tcp4 (established)
src: [host=127.0.0.1, port=56094]
dst: [host=127.0.0.1, port=56095]

tcp4 (established)
src: [host=127.0.0.1, port=56095]
dst: [host=127.0.0.1, port=56094]

tcp4 (established)
src: [host=127.0.0.1, port=56096]
dst: [host=127.0.0.1, port=56097]

tcp4 (established)
src: [host=127.0.0.1, port=56097]
dst: [host=127.0.0.1, port=56096]

tcp4 (established)
src: [host=127.0.0.1, port=56098]
dst: [host=127.0.0.1, port=56099]

tcp4 (established)
src: [host=127.0.0.1, port=56099]
dst: [host=127.0.0.1, port=56098]

tcp4 (established)
src: [host=172.17.100.73, port=135]
dst: [host=172.17.100.38, port=51684]

tcp4 (listen)
src: [host=172.17.100.73, port=139]
dst: [host=0.0.0.0, port=0]

tcp4 (established)
src: [host=172.17.100.73, port=445]
dst: [host=172.17.100.38, port=51683]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61825]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61826]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61827]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61828]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61833]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61834]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61835]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61836]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61837]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61838]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61839]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61840]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61842]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61843]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61844]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61845]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61850]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61851]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61853]

tcp4 (established)
src: [host=172.17.100.73, port=1433]
dst: [host=172.17.100.73, port=61854]

tcp4 (established)
src: [host=172.17.100.73, port=3389]
dst: [host=172.17.100.254, port=14636]

tcp4 (established)
src: [host=172.17.100.73, port=5059]
dst: [host=172.17.100.254, port=2714]

tcp4 (established)
src: [host=172.17.100.73, port=25002]
dst: [host=172.17.100.73, port=49710]

tcp4 (established)
src: [host=172.17.100.73, port=25002]
dst: [host=172.17.100.88, port=50443]

tcp4 (established)
src: [host=172.17.100.73, port=25002]
dst: [host=172.17.100.254, port=19788]

tcp4 (established)
src: [host=172.17.100.73, port=25002]
dst: [host=172.17.100.254, port=36160]

tcp4 (established)
src: [host=172.17.100.73, port=25002]
dst: [host=172.17.100.254, port=55858]

tcp4 (established)
src: [host=172.17.100.73, port=49666]
dst: [host=172.17.100.38, port=51685]

tcp4 (established)
src: [host=172.17.100.73, port=49710]
dst: [host=172.17.100.73, port=25002]

tcp4 (established)
src: [host=172.17.100.73, port=49729]
dst: [host=172.17.100.187, port=445]

tcp4 (established)
src: [host=172.17.100.73, port=49732]
dst: [host=172.17.100.184, port=445]

tcp4 (established)
src: [host=172.17.100.73, port=49733]
dst: [host=172.17.100.222, port=445]

tcp4 (established)
src: [host=172.17.100.73, port=52188]
dst: [host=4.213.25.241, port=443]

tcp4 (established)
src: [host=172.17.100.73, port=54176]
dst: [host=192.168.10.80, port=445]

tcp4 (established)
src: [host=172.17.100.73, port=61346]
dst: [host=172.17.100.91, port=445]

tcp4 (established)
src: [host=172.17.100.73, port=61825]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61826]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61827]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61828]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61833]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61834]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61835]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61836]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61837]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61838]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61839]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61840]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61842]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61843]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61844]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61845]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61850]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61851]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61853]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61854]
dst: [host=172.17.100.73, port=1433]

tcp4 (established)
src: [host=172.17.100.73, port=61869]
dst: [host=4.213.25.240, port=443]

tcp4 (established)
src: [host=172.17.100.73, port=61897]
dst: [host=20.189.173.15, port=443]

tcp4 (established)
src: [host=172.17.100.73, port=65277]
dst: [host=172.17.100.51, port=445]

tcp6 (listen)
src: [host=[::], port=80]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=135]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=445]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=1433]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=2383]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=3389]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5800]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5900]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=5985]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=25002]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=47001]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49664]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49665]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49666]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49667]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49668]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49670]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=49672]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=51528]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::], port=51529]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1434]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1550]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=1551]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=30523]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=49669]
dst: [host=[::], port=0]

tcp6 (listen)
src: [host=[::1], port=49686]
dst: [host=[::], port=0]

udp4 (listen)
src: [host=0.0.0.0, port=500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=1434]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=3389]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=4500]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5050]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5353]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=5355]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15000]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=15902]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=18901]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=19096]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=28446]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=28702]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=28958]
dst: [host=*, port=*]

udp4 (listen)
src: [host=0.0.0.0, port=51422]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.20.30.61, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.20.30.61, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.20.30.61, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.20.30.61, port=54434]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.113.99.73, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.113.99.73, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.113.99.73, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.113.99.73, port=54435]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.195.58.173, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.195.58.173, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.195.58.173, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=10.195.58.173, port=54437]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=54438]
dst: [host=*, port=*]

udp4 (listen)
src: [host=127.0.0.1, port=61278]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.73, port=137]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.73, port=138]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.73, port=1900]
dst: [host=*, port=*]

udp4 (listen)
src: [host=172.17.100.73, port=54436]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=1434]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=3389]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=4500]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15000]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=15902]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=18901]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=19096]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=28446]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=28702]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::], port=28958]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::1], port=1900]
dst: [host=*, port=*]

udp6 (listen)
src: [host=[::1], port=54433]
dst: [host=*, port=*]
34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus was able to find 42 open ports.

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/80/www

Port 80/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/135/epmap

Port 135/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/137/netbios-ns

Port 137/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/138

Port 138/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/139/smb

Port 139/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

Port 445/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/500

Port 500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/1433/mssql

Port 1433/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/1434

Port 1434/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/1900

Port 1900/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/2383

Port 2383/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/3389/msrdp

Port 3389/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/3389

Port 3389/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/4500

Port 4500/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5050

Port 5050/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5053

Port 5053/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5059

Port 5059/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5353

Port 5353/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/5355/llmnr

Port 5355/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5800/www

Port 5800/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5900/vnc

Port 5900/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/5985/www

Port 5985/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15000

Port 15000/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/15902

Port 15902/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/18901

Port 18901/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/19096

Port 19096/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/25002

Port 25002/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/28446

Port 28446/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/28702

Port 28702/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/28958

Port 28958/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/47001/www

Port 47001/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49664/dce-rpc

Port 49664/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49665/dce-rpc

Port 49665/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49666/dce-rpc

Port 49666/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49667/dce-rpc

Port 49667/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49668/dce-rpc

Port 49668/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49670/dce-rpc

Port 49670/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/49672/dce-rpc

Port 49672/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/51422

Port 51422/udp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/51528/www

Port 51528/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

tcp/51529/www

Port 51529/tcp was found to be open

34220 - Netstat Portscanner (WMI)
-
Synopsis
Remote open ports can be enumerated via WMI.
Description
Using the WMI interface, Nessus was able to run 'netstat' on the remote host to enumerate the open ports.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/09/16, Modified: 2025/12/15
Plugin Output

udp/54436

Port 54436/udp was found to be open

24272 - Network Interfaces Enumeration (WMI)
-
Synopsis
Nessus was able to obtain the list of network interfaces on the remote host.
Description
Nessus was able, via WMI queries, to extract a list of network interfaces on the remote host and the IP addresses attached to them.
Note that this plugin only enumerates IPv6 addresses for systems running Windows Vista or later.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/0

+ Network Interface Information :

- Network Interface = [00000001] Broadcom NetXtreme Gigabit Ethernet
- MAC Address = 40:A8:F0:20:84:37
- IPAddress/IPSubnet = 10.20.30.61/255.255.255.0

+ Network Interface Information :

- Network Interface = [00000002] Broadcom NetXtreme Gigabit Ethernet
- MAC Address = 40:A8:F0:20:84:36
- IPAddress/IPSubnet = 10.113.99.73/255.255.255.0

+ Network Interface Information :

- Network Interface = [00000003] Broadcom NetXtreme Gigabit Ethernet
- MAC Address = 40:A8:F0:20:84:35
- IPAddress/IPSubnet = 172.17.100.73/255.255.255.0

+ Network Interface Information :

- Network Interface = [00000004] Broadcom NetXtreme Gigabit Ethernet
- MAC Address = 40:A8:F0:20:84:34
- IPAddress/IPSubnet = 10.195.58.173/255.255.255.192


+ Routing Information :

Destination Netmask Gateway
----------- ------- -------
0.0.0.0 0.0.0.0 172.17.100.10
10.1.101.0 255.255.255.0 10.113.99.1
10.20.30.0 255.255.255.0 0.0.0.0
10.20.30.61 255.255.255.255 0.0.0.0
10.20.30.255 255.255.255.255 0.0.0.0
10.110.25.0 255.255.255.0 10.113.99.1
10.113.99.0 255.255.255.0 0.0.0.0
10.113.99.0 255.255.255.0 10.113.99.1
10.113.99.73 255.255.255.255 0.0.0.0
10.113.99.255 255.255.255.255 0.0.0.0
10.195.58.0 255.255.255.0 10.195.58.129
10.195.58.128 255.255.255.192 0.0.0.0
10.195.58.173 255.255.255.255 0.0.0.0
10.195.58.191 255.255.255.255 0.0.0.0
10.255.0.0 255.255.0.0 10.113.99.1
10.255.255.0 255.255.255.0 10.113.99.1
127.0.0.0 255.0.0.0 0.0.0.0
127.0.0.1 255.255.255.255 0.0.0.0
127.255.255.255 255.255.255.255 0.0.0.0
137.0.0.0 255.0.0.0 10.113.99.1
137.201.0.0 255.255.255.0 10.113.99.1
172.17.100.0 255.255.255.0 0.0.0.0
172.17.100.73 255.255.255.255 0.0.0.0
172.17.100.255 255.255.255.255 0.0.0.0
192.168.13.0 255.255.255.0 10.195.58.129
192.168.61.0 255.255.255.0 10.195.58.129
192.168.63.0 255.255.255.0 10.195.58.129
192.168.71.0 255.255.255.0 10.195.58.129
192.168.73.0 255.255.255.0 10.195.58.129
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
224.0.0.0 240.0.0.0 0.0.0.0
235.255.255.255 255.255.255.255 10.195.58.129
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
255.255.255.255 255.255.255.255 0.0.0.0
181646 - Notepad++ Installed (Windows)
-
Synopsis
Notepad++ is installed on the remote Windows host.
Description
Notepad++ is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/09/20, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\Program Files\Notepad++
Version : 8.6.6.0
209654 - OS Fingerprints Detected
-
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output

tcp/0


Following OS Fingerprints were found

Remote operating system : Microsoft Windows Server 2008
Confidence level : 56
Method : MLSinFP
Type : unknown
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter 14393
Confidence level : 80
Method : Misc
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 100
Method : SMB_OS
Type : general-purpose
Fingerprint : unknown

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 75
Method : HTTP
Type : general-purpose
Fingerprint : HTTP:Server: Microsoft-IIS/10.0


Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 70
Method : SinFP
Type : general-purpose
Fingerprint : SinFP:
P1:B11113:F0x12:W8192:O0204ffff:M1460:
P2:B11113:F0x12:W8192:O0204ffff010303080402080affffffff44454144:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191601_7_p=49667

Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 70
Method : smb
Type : general-purpose
Fingerprint : unknown

Following fingerprints could not be used to determine OS :
SSLcert:!:i/CN:GlobalSign RSA OV SSL CA 2018i/O:GlobalSign nv-sas/CN:www.lkp.net.ins/O:LKP SECURITIES LIMITED
f66174c5d8d4f20ea993126eca563ea908172c9b
i/CN:XHwakEyeSrvs/CN:XHwakEyeSrv
6e0f63bee9498a2b9226d04d867525eea71b4fde
i/CN:SSL_Self_Signed_Fallbacks/CN:SSL_Self_Signed_Fallback
74c7c0ee8fd38443543285ba6c68bd43d35acb82
11936 - OS Identification
-
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/06/03
Plugin Output

tcp/0


Remote operating system : Microsoft Windows Server 2016 Datacenter Build 14393
Confidence level : 100
Method : SMB_OS


The remote host is running Microsoft Windows Server 2016 Datacenter Build 14393

117887 - OS Security Patch Assessment Available
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials and enumerate OS security patch levels.
Description
Nessus was able to determine OS security patch levels by logging into the remote host and running commands to determine the version of the operating system and its components. The remote host was identified as an operating system or device that Nessus supports for patch and update assessment. The necessary information was obtained to perform these checks.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0516
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output

tcp/445/cifs

OS Security Patch Assessment is available.

Account : 172.17.100.73\tidua
Protocol : SMB

92426 - OpenSaveMRU History
-
Synopsis
Nessus was able to enumerate opened and saved files on the remote host.
Description
Nessus was able to generate a report on files that were opened using the shell dialog box or saved using the shell dialog box. This is the box that appears when you attempt to save a document or open a document in Windows Explorer.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

Open / Save report attached.

71462 - Oracle Java JRE Premier Support and Extended Support Version Detection
-
Synopsis
The remote host contains one or more versions of the Oracle Java JRE that require long-term support.
Description
According to its version, there is at least one install of Oracle (formerly Sun) Java JRE that is potentially under either Premier Support or Extended Support.

Note that both support programs require vendor contracts. Premier Support provides upgrades and security fixes for five years after the general availability (GA) date. Extended Support provides upgrades and security fixes for three years after Premier Support ends.
See Also
Solution
To continue receiving updates and security fixes, contact the vendor regarding Premier Support or Extended Support contracts.
Risk Factor
None
Plugin Information
Published: 2013/12/16, Modified: 2022/04/11
Plugin Output

tcp/445/cifs



The following Java JRE installs are in Extended Support status :

Path : C:\Program Files\Java\jre-1.8
Version : 8.0.401.10
Support dates : 2022-03-01 (end of Premier Support) / 2030-12-01 (end of Extended Support)

33545 - Oracle Java Runtime Environment (JRE) Detection
-
Synopsis
There is a Java runtime environment installed on the remote Windows host.
Description
One or more instances of Oracle's (formerly Sun's) Java Runtime Environment (JRE) is installed on the remote host. This may include private JREs bundled with the Java Development Kit (JDK).

- Additional instances of Java may be discovered if thorough tests are enabled.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0690
Plugin Information
Published: 2008/07/18, Modified: 2022/10/10
Plugin Output

tcp/0


Path : C:\Program Files\Java\jre-1.8\
Version : 8.0.401.10
Binary Location : C:\Program Files\Java\jre-1.8\bin\java.exe
66334 - Patch Report
-
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.

Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/12/15
Plugin Output

tcp/0



. You need to take the following 20 actions :

+ Install the following Microsoft patches :
- KB5071543 (101 vulnerabilities)The following KBs would be covered:
KB5063871, KB5065427, KB5066836, KB5055521, KB5052006,
KB5058383, KB5061010, KB5048671, KB5049993, KB5068864,
KB5062560, KB5053594, KB5041773, KB5043051, KB5044293,
KB5036899, KB5034767, KB5037763, KB5039214, KB5033373,
KB5034119, KB5046612, KB5040434, KB5035855, KB5029242,
KB5030213, KB5031362, KB5025228, KB5022838, KB5026363,
KB5027219, KB5021235, KB5022289, KB5032197, KB5028169,
KB5023697, KB5016622, KB5017305, KB5018411, KB5012596,
KB5010359, KB5013952, KB5014702, KB5008207, KB5009546,
KB5019964, KB5015808, KB5011495, KB5005043, KB5005573,
KB5006669, KB5001347, KB4601318, KB5003197, KB5003638,
KB5004948, KB4593226, KB4598243, KB5008601, KB5005393,
KB5000803, KB4571694, KB4565511, KB4577015, KB4580346,
KB4550929, KB4537764, KB4537806, KB4556813, KB4561616,
KB4567517, KB4530689, KB4534271, KB4534307, KB4586830,
KB4540670, KB4512517, KB4512495, KB4516044, KB4522010,
KB4516061, KB4524152, KB4519998, KB4519979, KB4493470,
KB4493473, KB4487026, KB4487006, KB4494440, KB4505052,
KB4499177, KB4503267, KB4503294, KB4509475, KB4480961,
KB4480977, KB4525236, KB4507460, KB4507459, KB4489882,
KB4489889
- KB4346087
- KB4091664
- KB2850016

[ Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104) (156103) ]

+ Action to take : Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life.

Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions.


[ Apache Tomcat 9.0.0.M1 < 9.0.110 (271694) ]

+ Action to take : Upgrade to Apache Tomcat version 9.0.110 or later.

+ Impact : Taking this action will resolve the following 20 different vulnerabilities :
CVE-2025-61795, CVE-2025-55754, CVE-2025-55752, CVE-2025-55668, CVE-2025-53506
CVE-2025-52520, CVE-2025-52434, CVE-2025-49125, CVE-2025-49124, CVE-2025-48989
CVE-2025-48988, CVE-2025-48976, CVE-2025-46701, CVE-2025-31651, CVE-2025-31650
CVE-2025-24813, CVE-2024-56337, CVE-2024-54677, CVE-2024-50379, CVE-2024-34750



[ KB4483229: Windows 10 Version 1607 and Windows Server 2016 December 2018 OOB Security Update (119769) ]

+ Action to take : Apply Cumulative Update KB4483229.


[ KB4577015: Windows 10 Version 1607 and Windows Server 2016 September 2020 Security Update (140417) ]

+ Action to take : Apply Cumulative Update KB4577015.

+ Impact : Taking this action will resolve the following 1130 different vulnerabilities :
CVE-2020-1587, CVE-2020-1584, CVE-2020-1579, CVE-2020-1577, CVE-2020-1570
CVE-2020-1568, CVE-2020-1567, CVE-2020-1566, CVE-2020-1565, CVE-2020-1564
CVE-2020-1562, CVE-2020-1561, CVE-2020-1558, CVE-2020-1557, CVE-2020-1556
CVE-2020-1554, CVE-2020-1553, CVE-2020-1552, CVE-2020-1550, CVE-2020-1549
CVE-2020-1538, CVE-2020-1537, CVE-2020-1534, CVE-2020-1533, CVE-2020-1531
CVE-2020-1530, CVE-2020-1529, CVE-2020-1527, CVE-2020-1526, CVE-2020-1525
CVE-2020-1522, CVE-2020-1521, CVE-2020-1520, CVE-2020-1519, CVE-2020-1518
CVE-2020-1517, CVE-2020-1516, CVE-2020-1515, CVE-2020-1513, CVE-2020-1512
CVE-2020-1511, CVE-2020-1509, CVE-2020-1492, CVE-2020-1490, CVE-2020-1489
CVE-2020-1488, CVE-2020-1487, CVE-2020-1486, CVE-2020-1485, CVE-2020-1484
CVE-2020-1478, CVE-2020-1477, CVE-2020-1476, CVE-2020-1475, CVE-2020-1474
CVE-2020-1473, CVE-2020-1472, CVE-2020-1470, CVE-2020-1468, CVE-2020-1467
CVE-2020-1466, CVE-2020-1464, CVE-2020-1463, CVE-2020-1462, CVE-2020-1438
CVE-2020-1437, CVE-2020-1436, CVE-2020-1435, CVE-2020-1434, CVE-2020-1433
CVE-2020-1432, CVE-2020-1430, CVE-2020-1429, CVE-2020-1428, CVE-2020-1427
CVE-2020-1421, CVE-2020-1420, CVE-2020-1419, CVE-2020-1413, CVE-2020-1412
CVE-2020-1411, CVE-2020-1410, CVE-2020-1409, CVE-2020-1408, CVE-2020-1407
CVE-2020-1406, CVE-2020-1404, CVE-2020-1403, CVE-2020-1402, CVE-2020-1401
CVE-2020-1400, CVE-2020-1399, CVE-2020-1398, CVE-2020-1397, CVE-2020-1396
CVE-2020-1395, CVE-2020-1393, CVE-2020-1390, CVE-2020-1389, CVE-2020-1388
CVE-2020-1385, CVE-2020-1384, CVE-2020-1383, CVE-2020-1380, CVE-2020-1379
CVE-2020-1378, CVE-2020-1377, CVE-2020-1374, CVE-2020-1373, CVE-2020-1371
CVE-2020-1370, CVE-2020-1369, CVE-2020-1368, CVE-2020-1365, CVE-2020-1364
CVE-2020-1362, CVE-2020-1361, CVE-2020-1360, CVE-2020-1359, CVE-2020-1358
CVE-2020-1357, CVE-2020-1356, CVE-2020-1354, CVE-2020-1353, CVE-2020-1352
CVE-2020-1351, CVE-2020-1348, CVE-2020-1346, CVE-2020-1344, CVE-2020-1339
CVE-2020-1337, CVE-2020-1336, CVE-2020-1334, CVE-2020-1333, CVE-2020-1317
CVE-2020-1316, CVE-2020-1315, CVE-2020-1314, CVE-2020-1311, CVE-2020-1310
CVE-2020-1309, CVE-2020-1305, CVE-2020-1304, CVE-2020-1302, CVE-2020-1301
CVE-2020-1300, CVE-2020-1299, CVE-2020-1294, CVE-2020-1293, CVE-2020-1291
CVE-2020-1287, CVE-2020-1283, CVE-2020-1282, CVE-2020-1281, CVE-2020-1279
CVE-2020-1278, CVE-2020-1272, CVE-2020-1271, CVE-2020-1270, CVE-2020-1269
CVE-2020-1267, CVE-2020-1266, CVE-2020-1264, CVE-2020-1263, CVE-2020-1262
CVE-2020-1261, CVE-2020-1260, CVE-2020-1259, CVE-2020-1257, CVE-2020-1255
CVE-2020-1254, CVE-2020-1253, CVE-2020-1251, CVE-2020-1249, CVE-2020-1247
CVE-2020-1246, CVE-2020-1241, CVE-2020-1239, CVE-2020-1236, CVE-2020-1235
CVE-2020-1234, CVE-2020-1232, CVE-2020-1231, CVE-2020-1230, CVE-2020-1220
CVE-2020-1219, CVE-2020-1216, CVE-2020-1215, CVE-2020-1214, CVE-2020-1213
CVE-2020-1212, CVE-2020-1211, CVE-2020-1208, CVE-2020-1207, CVE-2020-1203
CVE-2020-1202, CVE-2020-1197, CVE-2020-1196, CVE-2020-1194, CVE-2020-1191
CVE-2020-1190, CVE-2020-1189, CVE-2020-1188, CVE-2020-1187, CVE-2020-1186
CVE-2020-1185, CVE-2020-1184, CVE-2020-1179, CVE-2020-1176, CVE-2020-1175
CVE-2020-1174, CVE-2020-1164, CVE-2020-1160, CVE-2020-1158, CVE-2020-1157
CVE-2020-1156, CVE-2020-1154, CVE-2020-1153, CVE-2020-1149, CVE-2020-1147
CVE-2020-1144, CVE-2020-1143, CVE-2020-1141, CVE-2020-1139, CVE-2020-1138
CVE-2020-1136, CVE-2020-1134, CVE-2020-1132, CVE-2020-1131, CVE-2020-1126
CVE-2020-1125, CVE-2020-1124, CVE-2020-1123, CVE-2020-1117, CVE-2020-1116
CVE-2020-1114, CVE-2020-1113, CVE-2020-1112, CVE-2020-1108, CVE-2020-1093
CVE-2020-1092, CVE-2020-1090, CVE-2020-1088, CVE-2020-1086, CVE-2020-1085
CVE-2020-1084, CVE-2020-1082, CVE-2020-1081, CVE-2020-1079, CVE-2020-1078
CVE-2020-1077, CVE-2020-1076, CVE-2020-1073, CVE-2020-1072, CVE-2020-1071
CVE-2020-1070, CVE-2020-1068, CVE-2020-1067, CVE-2020-1064, CVE-2020-1062
CVE-2020-1061, CVE-2020-1060, CVE-2020-1058, CVE-2020-1056, CVE-2020-1054
CVE-2020-1051, CVE-2020-1048, CVE-2020-1046, CVE-2020-1037, CVE-2020-1035
CVE-2020-1028, CVE-2020-1021, CVE-2020-1010, CVE-2020-0986, CVE-2020-0963
CVE-2020-0916, CVE-2020-0915, CVE-2020-0909, CVE-2020-0898, CVE-2020-0897
CVE-2020-0896, CVE-2020-0887, CVE-2020-0885, CVE-2020-0883, CVE-2020-0882
CVE-2020-0881, CVE-2020-0880, CVE-2020-0879, CVE-2020-0877, CVE-2020-0874
CVE-2020-0871, CVE-2020-0869, CVE-2020-0868, CVE-2020-0867, CVE-2020-0866
CVE-2020-0865, CVE-2020-0864, CVE-2020-0861, CVE-2020-0860, CVE-2020-0859
CVE-2020-0858, CVE-2020-0857, CVE-2020-0853, CVE-2020-0849, CVE-2020-0848
CVE-2020-0847, CVE-2020-0845, CVE-2020-0844, CVE-2020-0843, CVE-2020-0842
CVE-2020-0841, CVE-2020-0840, CVE-2020-0834, CVE-2020-0833, CVE-2020-0832
CVE-2020-0831, CVE-2020-0830, CVE-2020-0829, CVE-2020-0828, CVE-2020-0827
CVE-2020-0826, CVE-2020-0824, CVE-2020-0823, CVE-2020-0822, CVE-2020-0820
CVE-2020-0819, CVE-2020-0818, CVE-2020-0817, CVE-2020-0816, CVE-2020-0814
CVE-2020-0810, CVE-2020-0809, CVE-2020-0806, CVE-2020-0804, CVE-2020-0803
CVE-2020-0802, CVE-2020-0801, CVE-2020-0800, CVE-2020-0799, CVE-2020-0798
CVE-2020-0797, CVE-2020-0793, CVE-2020-0791, CVE-2020-0788, CVE-2020-0787
CVE-2020-0786, CVE-2020-0785, CVE-2020-0783, CVE-2020-0781, CVE-2020-0780
CVE-2020-0779, CVE-2020-0778, CVE-2020-0777, CVE-2020-0776, CVE-2020-0775
CVE-2020-0774, CVE-2020-0773, CVE-2020-0772, CVE-2020-0771, CVE-2020-0770
CVE-2020-0769, CVE-2020-0768, CVE-2020-0767, CVE-2020-0756, CVE-2020-0755
CVE-2020-0754, CVE-2020-0753, CVE-2020-0752, CVE-2020-0750, CVE-2020-0749
CVE-2020-0748, CVE-2020-0747, CVE-2020-0745, CVE-2020-0744, CVE-2020-0743
CVE-2020-0742, CVE-2020-0739, CVE-2020-0738, CVE-2020-0737, CVE-2020-0735
CVE-2020-0734, CVE-2020-0732, CVE-2020-0731, CVE-2020-0730, CVE-2020-0729
CVE-2020-0728, CVE-2020-0727, CVE-2020-0726, CVE-2020-0725, CVE-2020-0724
CVE-2020-0723, CVE-2020-0722, CVE-2020-0721, CVE-2020-0720, CVE-2020-0719
CVE-2020-0716, CVE-2020-0715, CVE-2020-0713, CVE-2020-0712, CVE-2020-0710
CVE-2020-0709, CVE-2020-0708, CVE-2020-0707, CVE-2020-0706, CVE-2020-0705
CVE-2020-0704, CVE-2020-0703, CVE-2020-0698, CVE-2020-0691, CVE-2020-0690
CVE-2020-0689, CVE-2020-0686, CVE-2020-0684, CVE-2020-0683, CVE-2020-0682
CVE-2020-0681, CVE-2020-0680, CVE-2020-0679, CVE-2020-0678, CVE-2020-0677
CVE-2020-0676, CVE-2020-0675, CVE-2020-0674, CVE-2020-0673, CVE-2020-0670
CVE-2020-0668, CVE-2020-0667, CVE-2020-0666, CVE-2020-0665, CVE-2020-0662
CVE-2020-0661, CVE-2020-0660, CVE-2020-0659, CVE-2020-0658, CVE-2020-0657
CVE-2020-0655, CVE-2020-0645, CVE-2019-9518, CVE-2019-9514, CVE-2019-9513
CVE-2019-9512, CVE-2019-9511, CVE-2019-9506, CVE-2019-1456, CVE-2019-1454
CVE-2019-1439, CVE-2019-1438, CVE-2019-1436, CVE-2019-1435, CVE-2019-1433
CVE-2019-1429, CVE-2019-1428, CVE-2019-1427, CVE-2019-1426, CVE-2019-1424
CVE-2019-1422, CVE-2019-1420, CVE-2019-1419, CVE-2019-1418, CVE-2019-1417
CVE-2019-1415, CVE-2019-1413, CVE-2019-1411, CVE-2019-1409, CVE-2019-1408
CVE-2019-1407, CVE-2019-1406, CVE-2019-1405, CVE-2019-1399, CVE-2019-1397
CVE-2019-1396, CVE-2019-1395, CVE-2019-1394, CVE-2019-1393, CVE-2019-1391
CVE-2019-1390, CVE-2019-1389, CVE-2019-1388, CVE-2019-1384, CVE-2019-1383
CVE-2019-1382, CVE-2019-1381, CVE-2019-1380, CVE-2019-1374, CVE-2019-1371
CVE-2019-1366, CVE-2019-1365, CVE-2019-1359, CVE-2019-1358, CVE-2019-1357
CVE-2019-1356, CVE-2019-1347, CVE-2019-1346, CVE-2019-1345, CVE-2019-1344
CVE-2019-1343, CVE-2019-1342, CVE-2019-1341, CVE-2019-1339, CVE-2019-1335
CVE-2019-1334, CVE-2019-1333, CVE-2019-1326, CVE-2019-1325, CVE-2019-1319
CVE-2019-1318, CVE-2019-1317, CVE-2019-1316, CVE-2019-1315, CVE-2019-1311
CVE-2019-1308, CVE-2019-1307, CVE-2019-1300, CVE-2019-1298, CVE-2019-1293
CVE-2019-1292, CVE-2019-1291, CVE-2019-1290, CVE-2019-1289, CVE-2019-1287
CVE-2019-1286, CVE-2019-1285, CVE-2019-1282, CVE-2019-1280, CVE-2019-1278
CVE-2019-1274, CVE-2019-1272, CVE-2019-1271, CVE-2019-1270, CVE-2019-1269
CVE-2019-1268, CVE-2019-1267, CVE-2019-1256, CVE-2019-1254, CVE-2019-1252
CVE-2019-1250, CVE-2019-1249, CVE-2019-1248, CVE-2019-1247, CVE-2019-1246
CVE-2019-1245, CVE-2019-1244, CVE-2019-1243, CVE-2019-1242, CVE-2019-1241
CVE-2019-1240, CVE-2019-1238, CVE-2019-1237, CVE-2019-1236, CVE-2019-1235
CVE-2019-1232, CVE-2019-1221, CVE-2019-1220, CVE-2019-1219, CVE-2019-1216
CVE-2019-1215, CVE-2019-1214, CVE-2019-1212, CVE-2019-1208, CVE-2019-1206
CVE-2019-1198, CVE-2019-1197, CVE-2019-1195, CVE-2019-1194, CVE-2019-1193
CVE-2019-1192, CVE-2019-1187, CVE-2019-1186, CVE-2019-1183, CVE-2019-1182
CVE-2019-1181, CVE-2019-1180, CVE-2019-1179, CVE-2019-1178, CVE-2019-1177
CVE-2019-1176, CVE-2019-1172, CVE-2019-1168, CVE-2019-1166, CVE-2019-1164
CVE-2019-1163, CVE-2019-1162, CVE-2019-1159, CVE-2019-1158, CVE-2019-1157
CVE-2019-1156, CVE-2019-1155, CVE-2019-1153, CVE-2019-1152, CVE-2019-1151
CVE-2019-1150, CVE-2019-1149, CVE-2019-1148, CVE-2019-1147, CVE-2019-1146
CVE-2019-1145, CVE-2019-1144, CVE-2019-1143, CVE-2019-1142, CVE-2019-1140
CVE-2019-1139, CVE-2019-1138, CVE-2019-1133, CVE-2019-1130, CVE-2019-1126
CVE-2019-1125, CVE-2019-11135, CVE-2019-1113, CVE-2019-11091, CVE-2019-1108
CVE-2019-1107, CVE-2019-1106, CVE-2019-1104, CVE-2019-1103, CVE-2019-1102
CVE-2019-1097, CVE-2019-1096, CVE-2019-1095, CVE-2019-1094, CVE-2019-1093
CVE-2019-1092, CVE-2019-1091, CVE-2019-1089, CVE-2019-1088, CVE-2019-1087
CVE-2019-1086, CVE-2019-1085, CVE-2019-1083, CVE-2019-1082, CVE-2019-1081
CVE-2019-1080, CVE-2019-1078, CVE-2019-1073, CVE-2019-1071, CVE-2019-1069
CVE-2019-1067, CVE-2019-1064, CVE-2019-1063, CVE-2019-1062, CVE-2019-1060
CVE-2019-1059, CVE-2019-1057, CVE-2019-1056, CVE-2019-1055, CVE-2019-1054
CVE-2019-1053, CVE-2019-1052, CVE-2019-1051, CVE-2019-1050, CVE-2019-1046
CVE-2019-1043, CVE-2019-1040, CVE-2019-1039, CVE-2019-1038, CVE-2019-1030
CVE-2019-1028, CVE-2019-1025, CVE-2019-1023, CVE-2019-1019, CVE-2019-1018
CVE-2019-1017, CVE-2019-1014, CVE-2019-1012, CVE-2019-1010, CVE-2019-1007
CVE-2019-1006, CVE-2019-1005, CVE-2019-1004, CVE-2019-1003, CVE-2019-1002
CVE-2019-1001, CVE-2019-0999, CVE-2019-0995, CVE-2019-0993, CVE-2019-0992
CVE-2019-0991, CVE-2019-0990, CVE-2019-0989, CVE-2019-0988, CVE-2019-0986
CVE-2019-0984, CVE-2019-0983, CVE-2019-0981, CVE-2019-0980, CVE-2019-0975
CVE-2019-0974, CVE-2019-0973, CVE-2019-0972, CVE-2019-0966, CVE-2019-0961
CVE-2019-0948, CVE-2019-0943, CVE-2019-0942, CVE-2019-0941, CVE-2019-0940
CVE-2019-0938, CVE-2019-0936, CVE-2019-0933, CVE-2019-0930, CVE-2019-0928
CVE-2019-0927, CVE-2019-0925, CVE-2019-0924, CVE-2019-0923, CVE-2019-0922
CVE-2019-0921, CVE-2019-0920, CVE-2019-0918, CVE-2019-0917, CVE-2019-0916
CVE-2019-0915, CVE-2019-0914, CVE-2019-0913, CVE-2019-0912, CVE-2019-0911
CVE-2019-0909, CVE-2019-0908, CVE-2019-0907, CVE-2019-0906, CVE-2019-0905
CVE-2019-0904, CVE-2019-0903, CVE-2019-0902, CVE-2019-0901, CVE-2019-0900
CVE-2019-0899, CVE-2019-0898, CVE-2019-0897, CVE-2019-0896, CVE-2019-0895
CVE-2019-0894, CVE-2019-0893, CVE-2019-0891, CVE-2019-0890, CVE-2019-0889
CVE-2019-0888, CVE-2019-0887, CVE-2019-0886, CVE-2019-0885, CVE-2019-0884
CVE-2019-0882, CVE-2019-0881, CVE-2019-0880, CVE-2019-0879, CVE-2019-0877
CVE-2019-0864, CVE-2019-0863, CVE-2019-0862, CVE-2019-0861, CVE-2019-0860
CVE-2019-0859, CVE-2019-0856, CVE-2019-0853, CVE-2019-0851, CVE-2019-0849
CVE-2019-0848, CVE-2019-0847, CVE-2019-0846, CVE-2019-0845, CVE-2019-0844
CVE-2019-0842, CVE-2019-0839, CVE-2019-0838, CVE-2019-0836, CVE-2019-0835
CVE-2019-0829, CVE-2019-0821, CVE-2019-0820, CVE-2019-0814, CVE-2019-0812
CVE-2019-0811, CVE-2019-0810, CVE-2019-0806, CVE-2019-0805, CVE-2019-0803
CVE-2019-0802, CVE-2019-0797, CVE-2019-0796, CVE-2019-0795, CVE-2019-0794
CVE-2019-0793, CVE-2019-0792, CVE-2019-0791, CVE-2019-0790, CVE-2019-0785
CVE-2019-0784, CVE-2019-0783, CVE-2019-0782, CVE-2019-0780, CVE-2019-0779
CVE-2019-0776, CVE-2019-0775, CVE-2019-0774, CVE-2019-0773, CVE-2019-0772
CVE-2019-0771, CVE-2019-0770, CVE-2019-0769, CVE-2019-0767, CVE-2019-0766
CVE-2019-0765, CVE-2019-0764, CVE-2019-0763, CVE-2019-0761, CVE-2019-0759
CVE-2019-0758, CVE-2019-0756, CVE-2019-0755, CVE-2019-0754, CVE-2019-0753
CVE-2019-0752, CVE-2019-0746, CVE-2019-0739, CVE-2019-0736, CVE-2019-0735
CVE-2019-0734, CVE-2019-0733, CVE-2019-0732, CVE-2019-0731, CVE-2019-0730
CVE-2019-0727, CVE-2019-0725, CVE-2019-0723, CVE-2019-0722, CVE-2019-0720
CVE-2019-0719, CVE-2019-0718, CVE-2019-0716, CVE-2019-0715, CVE-2019-0714
CVE-2019-0713, CVE-2019-0712, CVE-2019-0711, CVE-2019-0710, CVE-2019-0709
CVE-2019-0707, CVE-2019-0704, CVE-2019-0703, CVE-2019-0702, CVE-2019-0696
CVE-2019-0695, CVE-2019-0690, CVE-2019-0688, CVE-2019-0685, CVE-2019-0680
CVE-2019-0678, CVE-2019-0676, CVE-2019-0667, CVE-2019-0666, CVE-2019-0665
CVE-2019-0663, CVE-2019-0662, CVE-2019-0660, CVE-2019-0659, CVE-2019-0657
CVE-2019-0656, CVE-2019-0655, CVE-2019-0654, CVE-2019-0652, CVE-2019-0651
CVE-2019-0645, CVE-2019-0644, CVE-2019-0642, CVE-2019-0636, CVE-2019-0635
CVE-2019-0633, CVE-2019-0632, CVE-2019-0631, CVE-2019-0630, CVE-2019-0628
CVE-2019-0627, CVE-2019-0626, CVE-2019-0625, CVE-2019-0623, CVE-2019-0621
CVE-2019-0620, CVE-2019-0619, CVE-2019-0618, CVE-2019-0617, CVE-2019-0616
CVE-2019-0615, CVE-2019-0614, CVE-2019-0613, CVE-2019-0609, CVE-2019-0608
CVE-2019-0606, CVE-2019-0605, CVE-2019-0603, CVE-2019-0602, CVE-2019-0601
CVE-2019-0600, CVE-2019-0599, CVE-2019-0598, CVE-2019-0597, CVE-2019-0596
CVE-2019-0595, CVE-2019-0593, CVE-2019-0591, CVE-2019-0590, CVE-2019-0584
CVE-2019-0583, CVE-2019-0582, CVE-2019-0581, CVE-2019-0580, CVE-2019-0579
CVE-2019-0578, CVE-2019-0577, CVE-2019-0576, CVE-2019-0575, CVE-2019-0574
CVE-2019-0573, CVE-2019-0572, CVE-2019-0571, CVE-2019-0570, CVE-2019-0569
CVE-2019-0567, CVE-2019-0566, CVE-2019-0555, CVE-2019-0554, CVE-2019-0552
CVE-2019-0551, CVE-2019-0549, CVE-2019-0545, CVE-2019-0543, CVE-2019-0541
CVE-2019-0539, CVE-2019-0538, CVE-2019-0536, CVE-2018-8643, CVE-2018-8641
CVE-2018-8639, CVE-2018-8634, CVE-2018-8631, CVE-2018-8629, CVE-2018-8626
CVE-2018-8625, CVE-2018-8624, CVE-2018-8619, CVE-2018-8618, CVE-2018-8617
CVE-2018-8612, CVE-2018-8611, CVE-2018-8599, CVE-2018-8596, CVE-2018-8595
CVE-2018-8588, CVE-2018-8584, CVE-2018-8565, CVE-2018-8564, CVE-2018-8562
CVE-2018-8561, CVE-2018-8557, CVE-2018-8556, CVE-2018-8555, CVE-2018-8553
CVE-2018-8552, CVE-2018-8550, CVE-2018-8549, CVE-2018-8547, CVE-2018-8544
CVE-2018-8543, CVE-2018-8542, CVE-2018-8540, CVE-2018-8517, CVE-2018-8514
CVE-2018-8505, CVE-2018-8503, CVE-2018-8497, CVE-2018-8495, CVE-2018-8494
CVE-2018-8493, CVE-2018-8492, CVE-2018-8491, CVE-2018-8490, CVE-2018-8489
CVE-2018-8486, CVE-2018-8485, CVE-2018-8484, CVE-2018-8482, CVE-2018-8481
CVE-2018-8477, CVE-2018-8476, CVE-2018-8475, CVE-2018-8472, CVE-2018-8471
CVE-2018-8470, CVE-2018-8469, CVE-2018-8468, CVE-2018-8467, CVE-2018-8466
CVE-2018-8465, CVE-2018-8464, CVE-2018-8462, CVE-2018-8460, CVE-2018-8457
CVE-2018-8455, CVE-2018-8453, CVE-2018-8452, CVE-2018-8450, CVE-2018-8449
CVE-2018-8447, CVE-2018-8446, CVE-2018-8443, CVE-2018-8442, CVE-2018-8440
CVE-2018-8439, CVE-2018-8438, CVE-2018-8435, CVE-2018-8434, CVE-2018-8433
CVE-2018-8425, CVE-2018-8424, CVE-2018-8423, CVE-2018-8421, CVE-2018-8420
CVE-2018-8419, CVE-2018-8417, CVE-2018-8415, CVE-2018-8413, CVE-2018-8411
CVE-2018-8410, CVE-2018-8408, CVE-2018-8407, CVE-2018-8406, CVE-2018-8405
CVE-2018-8404, CVE-2018-8403, CVE-2018-8401, CVE-2018-8398, CVE-2018-8394
CVE-2018-8393, CVE-2018-8392, CVE-2018-8389, CVE-2018-8388, CVE-2018-8385
CVE-2018-8381, CVE-2018-8373, CVE-2018-8372, CVE-2018-8371, CVE-2018-8370
CVE-2018-8367, CVE-2018-8360, CVE-2018-8358, CVE-2018-8357, CVE-2018-8356
CVE-2018-8355, CVE-2018-8354, CVE-2018-8353, CVE-2018-8351, CVE-2018-8349
CVE-2018-8348, CVE-2018-8347, CVE-2018-8345, CVE-2018-8344, CVE-2018-8343
CVE-2018-8341, CVE-2018-8340, CVE-2018-8339, CVE-2018-8335, CVE-2018-8333
CVE-2018-8332, CVE-2018-8330, CVE-2018-8320, CVE-2018-8316, CVE-2018-8315
CVE-2018-8313, CVE-2018-8309, CVE-2018-8308, CVE-2018-8307, CVE-2018-8304
CVE-2018-8296, CVE-2018-8291, CVE-2018-8290, CVE-2018-8288, CVE-2018-8287
CVE-2018-8284, CVE-2018-8282, CVE-2018-8280, CVE-2018-8275, CVE-2018-8271
CVE-2018-8267, CVE-2018-8266, CVE-2018-8260, CVE-2018-8256, CVE-2018-8253
CVE-2018-8251, CVE-2018-8242, CVE-2018-8239, CVE-2018-8236, CVE-2018-8235
CVE-2018-8234, CVE-2018-8231, CVE-2018-8229, CVE-2018-8226, CVE-2018-8225
CVE-2018-8222, CVE-2018-8221, CVE-2018-8219, CVE-2018-8217, CVE-2018-8216
CVE-2018-8215, CVE-2018-8214, CVE-2018-8213, CVE-2018-8212, CVE-2018-8210
CVE-2018-8209, CVE-2018-8208, CVE-2018-8207, CVE-2018-8206, CVE-2018-8205
CVE-2018-8204, CVE-2018-8202, CVE-2018-8201, CVE-2018-8200, CVE-2018-8169
CVE-2018-8125, CVE-2018-3646, CVE-2018-3620, CVE-2018-3615, CVE-2018-12207
CVE-2018-12130, CVE-2018-12127, CVE-2018-12126, CVE-2018-1040, CVE-2018-1036
CVE-2018-0982, CVE-2018-0978, CVE-2018-0965, CVE-2018-0952, CVE-2018-0949



[ MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080) (70337) ]

+ Action to take : Microsoft has released a set of patches for Excel 2007, Excel 2010, Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and Office Compatibility Pack.

+ Impact : Taking this action will resolve the following 18 different vulnerabilities :
CVE-2013-3890, CVE-2013-3889, CVE-2013-3159, CVE-2013-3158, CVE-2013-3157
CVE-2013-3156, CVE-2013-3155, CVE-2013-1315, CVE-2012-2543, CVE-2012-1887
CVE-2012-1886, CVE-2012-1885, CVE-2012-1847, CVE-2012-0185, CVE-2012-0184
CVE-2012-0143, CVE-2012-0142, CVE-2012-0141


[ MS13-094: Vulnerability in Microsoft Outlook Could Allow Information Disclosure (2894514) (70852) ]

+ Action to take : Microsoft has released a set of patches for Office 2007, 2010, 2013 and 2013 RT.

+ Impact : Taking this action will resolve the following 2 different vulnerabilities :
CVE-2013-3905, CVE-2013-3870


[ Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144) (240630) ]

+ Action to take : Upgrade to Notepad++ 8.8.2 or later.


[ Oracle Java SE Multiple Vulnerabilities (October 2025 CPU) (271249) ]

+ Action to take : Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory.

+ Impact : Taking this action will resolve the following 94 different vulnerabilities :
CVE-2025-6558, CVE-2025-61748, CVE-2025-53066, CVE-2025-53057, CVE-2025-50106
CVE-2025-50063, CVE-2025-50059, CVE-2025-43265, CVE-2025-43240, CVE-2025-43228
CVE-2025-43227, CVE-2025-43216, CVE-2025-43212, CVE-2025-43211, CVE-2025-32415
CVE-2025-32414, CVE-2025-31278, CVE-2025-31273, CVE-2025-31257, CVE-2025-30761
CVE-2025-30754, CVE-2025-30752, CVE-2025-30749, CVE-2025-30698, CVE-2025-30691
CVE-2025-27113, CVE-2025-24928, CVE-2025-24855, CVE-2025-24189, CVE-2025-24162
CVE-2025-24158, CVE-2025-24150, CVE-2025-24143, CVE-2025-23085, CVE-2025-23084
CVE-2025-23083, CVE-2025-21587, CVE-2025-21502, CVE-2025-0509, CVE-2024-56171
CVE-2024-55549, CVE-2024-54543, CVE-2024-54534, CVE-2024-54508, CVE-2024-54505
CVE-2024-54502, CVE-2024-54479, CVE-2024-47778, CVE-2024-47777, CVE-2024-47776
CVE-2024-47775, CVE-2024-47606, CVE-2024-47597, CVE-2024-47596, CVE-2024-47546
CVE-2024-47545, CVE-2024-47544, CVE-2024-44309, CVE-2024-44308, CVE-2024-44296
CVE-2024-44244, CVE-2024-44187, CVE-2024-44185, CVE-2024-40896, CVE-2024-40866
CVE-2024-36138, CVE-2024-27856, CVE-2024-25062, CVE-2024-22020, CVE-2024-21892
CVE-2024-21235, CVE-2024-21217, CVE-2024-21211, CVE-2024-21210, CVE-2024-21208
CVE-2024-21147, CVE-2024-21145, CVE-2024-21144, CVE-2024-21140, CVE-2024-21138
CVE-2024-21131, CVE-2024-21098, CVE-2024-21094, CVE-2024-21085, CVE-2024-21068
CVE-2024-21012, CVE-2024-21011, CVE-2024-21005, CVE-2024-21004, CVE-2024-21003
CVE-2024-21002, CVE-2024-20954, CVE-2023-41993, CVE-2023-32643


[ RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088) (248462) ]

+ Action to take : Upgrade to RARLAB WinRAR version 7.13 or later.

+ Impact : Taking this action will resolve the following 7 different vulnerabilities :
CVE-2025-8088, CVE-2025-6218, CVE-2025-31334, CVE-2024-36052, CVE-2024-30370
CVE-2023-40477, CVE-2023-38831


[ Security Updates for Microsoft .NET Framework (October 2020) (141503) ]

+ Action to take : Microsoft has released security updates for Microsoft .NET Framework.

+ Impact : Taking this action will resolve the following 30 different vulnerabilities :
CVE-2020-16937, CVE-2020-1476, CVE-2020-1147, CVE-2020-1108, CVE-2020-1066
CVE-2020-1046, CVE-2020-0646, CVE-2020-0606, CVE-2020-0605, CVE-2019-1142
CVE-2019-1113, CVE-2019-1083, CVE-2019-1006, CVE-2019-0981, CVE-2019-0980
CVE-2019-0864, CVE-2019-0820, CVE-2019-0663, CVE-2019-0657, CVE-2019-0613
CVE-2019-0545, CVE-2018-8540, CVE-2018-8517, CVE-2018-8421, CVE-2018-8360
CVE-2018-1039, CVE-2018-0765, CVE-2017-8759, CVE-2017-0248, CVE-2017-0160



[ Security Updates for Microsoft Office Products (March 2021) (147218) ]

+ Action to take : Microsoft has released the following security updates to address this issue:
-KB4493228
-KB4493203
-KB4504703
-KB4493225
-KB4493200
-KB4493214

+ Impact : Taking this action will resolve the following 59 different vulnerabilities :
CVE-2021-27059, CVE-2021-27057, CVE-2021-27054, CVE-2021-24108, CVE-2017-8663
CVE-2017-8572, CVE-2017-8571, CVE-2017-8508, CVE-2017-8507, CVE-2017-8506
CVE-2017-0204, CVE-2017-0106, CVE-2014-4117, CVE-2014-1809, CVE-2014-1761
CVE-2014-1758, CVE-2014-1757, CVE-2014-0260, CVE-2014-0259, CVE-2014-0258
CVE-2013-5057, CVE-2013-3858, CVE-2013-3857, CVE-2013-3856, CVE-2013-3855
CVE-2013-3854, CVE-2013-3853, CVE-2013-3852, CVE-2013-3851, CVE-2013-3850
CVE-2013-3849, CVE-2013-3848, CVE-2013-3847, CVE-2013-3160, CVE-2013-1329
CVE-2013-1328, CVE-2013-1327, CVE-2013-1323, CVE-2013-1322, CVE-2013-1321
CVE-2013-1320, CVE-2013-1319, CVE-2013-1318, CVE-2013-1317, CVE-2013-1316
CVE-2012-2539, CVE-2012-2528, CVE-2012-2524, CVE-2012-1856, CVE-2012-0182
CVE-2012-0158, CVE-2011-1990, CVE-2011-1989, CVE-2011-1988, CVE-2011-1987
CVE-2011-1986, CVE-2011-1983, CVE-2011-1982, CVE-2011-1980


[ Security Updates for Microsoft SQL Server (November 2025) (275459) ]

+ Action to take : Microsoft has released security updates for Microsoft SQL Server.

+ Impact : Taking this action will resolve the following 100 different vulnerabilities :
CVE-2025-59499, CVE-2025-55227, CVE-2025-53727, CVE-2025-49719, CVE-2025-49718
CVE-2025-49717, CVE-2025-47997, CVE-2024-49043, CVE-2024-49021, CVE-2024-49018
CVE-2024-49017, CVE-2024-49016, CVE-2024-49015, CVE-2024-49014, CVE-2024-49013
CVE-2024-49012, CVE-2024-49011, CVE-2024-49010, CVE-2024-49009, CVE-2024-49008
CVE-2024-49007, CVE-2024-49006, CVE-2024-49005, CVE-2024-49004, CVE-2024-49003
CVE-2024-49002, CVE-2024-49001, CVE-2024-49000, CVE-2024-48999, CVE-2024-48998
CVE-2024-48997, CVE-2024-48996, CVE-2024-48995, CVE-2024-48994, CVE-2024-48993
CVE-2024-43474, CVE-2024-43462, CVE-2024-43459, CVE-2024-38255, CVE-2024-38088
CVE-2024-38087, CVE-2024-37980, CVE-2024-37966, CVE-2024-37965, CVE-2024-37342
CVE-2024-37341, CVE-2024-37340, CVE-2024-37339, CVE-2024-37338, CVE-2024-37337
CVE-2024-37336, CVE-2024-37335, CVE-2024-37334, CVE-2024-37333, CVE-2024-37332
CVE-2024-37331, CVE-2024-37330, CVE-2024-37329, CVE-2024-37328, CVE-2024-37327
CVE-2024-37326, CVE-2024-37324, CVE-2024-37323, CVE-2024-37322, CVE-2024-37321
CVE-2024-37320, CVE-2024-37319, CVE-2024-37318, CVE-2024-35272, CVE-2024-35271
CVE-2024-35256, CVE-2024-28928, CVE-2024-26191, CVE-2024-26186, CVE-2024-21907
CVE-2024-21449, CVE-2024-21428, CVE-2024-21425, CVE-2024-21415, CVE-2024-21414
CVE-2024-21398, CVE-2024-21373, CVE-2024-21335, CVE-2024-21333, CVE-2024-21332
CVE-2024-21331, CVE-2024-21317, CVE-2024-21308, CVE-2024-21303, CVE-2024-20701
CVE-2023-36728, CVE-2023-23384, CVE-2023-21718, CVE-2023-21713, CVE-2023-21705
CVE-2023-21704, CVE-2023-21568, CVE-2023-21528, CVE-2022-29143, CVE-2021-1636



[ Security Updates for Microsoft SQL Server OLE DB Driver (July 2024) (205300) ]

+ Action to take : Microsoft has released security updates for the Microsoft SQL OLE DB Driver.


[ Security Updates for Outlook (January 2019) (121027) ]

+ Action to take : Microsoft has released the following security updates to address this issue:
-KB4461595
-KB4461601
-KB4461623

For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update.

+ Impact : Taking this action will resolve the following 14 different vulnerabilities :
CVE-2019-0559, CVE-2018-8587, CVE-2018-8582, CVE-2018-8579, CVE-2018-8576
CVE-2018-8558, CVE-2018-8524, CVE-2018-8522, CVE-2018-8244, CVE-2018-0852
CVE-2018-0850, CVE-2018-0791, CVE-2017-11776, CVE-2017-11774


[ Security Updates for SQL Server Management Studio (April 2025) (234220) ]

+ Action to take : Microsoft has released SSMS version 20.2.1 to address this issue.


[ Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803) (276819) ]

+ Action to take : Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later.

206777 - Postman Installed (Windows)
-
Synopsis
Postman is installed on the remote Windows host.
Description
Postman is installed on the remote Windows host.

Note. To detect the software, customers need to use an account that is used to install the software, or one that has the administrative privileges on the target.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/09/09, Modified: 2025/12/15
Plugin Output

tcp/0


Path : C:\ProgramData\Production\Postman
Version : 11.69.2

122422 - RARLAB WinRAR Installed (Windows)
-
Synopsis
An archive manager is installed on the remote Windows host.
Description
RARLAB WinRaR, an archive manager, is installed on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0706
Plugin Information
Published: 2019/02/26, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


Path : C:\Program Files\WinRAR\WinRAR.exe
Version : 5.90.0.0

92428 - Recent File History
-
Synopsis
Nessus was able to enumerate recently opened files on the remote host.
Description
Nessus was able to gather evidence of files opened by file type from the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\Users\LKPAdmin\AppData\Roaming\Microsoft\Windows\Recent\XTPL.lnk

Recent files found in registry and appdata attached.
92429 - Recycle Bin Files
-
Synopsis
Nessus was able to enumerate files in the recycle bin on the remote host.
Description
Nessus was able to generate a list of all files found in $Recycle.Bin subdirectories.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

C:\\$Recycle.Bin\\.
C:\\$Recycle.Bin\\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$I8UYGYF
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\8400
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\AppConfigValidator.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\AudioButtons.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\AutoUpdate.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\C1.C1Zip.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\C1.Common.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\C1.Win.C1FlexGrid.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\C1.Win.C1TrueDBGrid.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\CheckedComboBox.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ClassLibrary---.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ClassLibrary.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ClassLibrary2012.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ClientServer.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\closeButton.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Config
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.BonusSkins.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Charts.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.CodeRush.Common.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.CodeRush.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.CodeRush.Extensions.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.CodeRush.PlugInCore.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Data.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Design.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Controls.Data.v6.3.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Controls.Utils.v6.3.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Controls.XtraEditors.v6.3.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Controls.XtraGrid.v6.3.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Controls.XtraLayout.v6.3.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Parser.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.DXCore.Platform.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.OfficeSkins.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.PivotGrid.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Printing.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.RichEdit.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.SpellChecker.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Utils.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Xpf.LayoutControl.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.Xpo.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraBars.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraCharts.v10.1.UI.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraCharts.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraCharts.v11.1.UI.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraEditors.v11.1.Design.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraEditors.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraGauges.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraGauges.v11.1.Win.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraGrid.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraLayout.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraNavBar.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraPivotGrid.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraReports.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraRichEdit.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraScheduler.v11.1.Core.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraScheduler.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraScheduler.v11.1.Extensions.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraSpellChecker.v10.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraSpellChecker.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraTreeList.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\DevExpress.XtraVerticalGrid.v11.1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\EnvDTE80.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Extensibility.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\FileData
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\FormSettings.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\gear1.gif
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\GreenCircleWhite.png
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\GridSettings-1.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\GridSettings.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\HeaderLine.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Interop.IWshRuntimeLibrary.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\LicenceStructures.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\LimitStructure.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Logs
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\LongShortReport_Util_999999
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\MachineID.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\mail.htm
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.MSXML.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.Office.Interop.Excel.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.Vbe.Interop.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.OLE.Interop.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.ProjectAggregator.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.Shell.Interop.8.0.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.Shell.Interop.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.TextManager.Interop.8.0.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.TextManager.Interop.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Microsoft.VisualStudio.VSHelp.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\MultiLabel.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Newtonsoft.Json.Net20.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Notification.wav
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\office.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Output Files
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Output Files_20241018
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\PKI.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\PKInfrastructure.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\pleasewait.gif
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\PointerStructures.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\PriceCharts.exe
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\RedCircleWhite.png
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ScripMaster.bin
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Settings.dat
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\settlement
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\ShortcutKeys.txt
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\stdole.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\temp.jpg
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Thumbs.db
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\unins000.dat
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\UTIL.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\version.bin
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\vjscor.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\vjslib.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\VSLangProj.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\VSLangProj2.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\VSLangProj80.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\WinSCPnet.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xAboutUs.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xAddon.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Xceed.Chart.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\Xceed.Chart.GraphicsGL.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xCommonStruct.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkEyeClient.exe
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkEyeClient.gst
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkEyeClient.vshost.exe
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkeyeClientUtil.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkeyeClient_Def.gst
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkEyeStructures.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xHawkEyeStructures.dll_old
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xMail.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xNotifier.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xtb.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xtb.xml
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\XTR
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\XTR1
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\xtrem.wav
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\XTR_2
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\XTR_20240804
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\zlib.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\zlib64.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-1005\$R8UYGYF\zlibwapi.dll
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I01CN4Y.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I0C72V6.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I0EW9TN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I17KITF.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I1CXE6M.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I2800FM.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I2JT1O2.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I2X2IZ3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I2ZQTA4.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I2ZY6RA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I31IRZW.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I321IMU.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I3EA3H7.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I3FTU8H.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I40JXV9
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I4GH78E.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I4U9GJS.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I5AQOZZ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I5GPS1R.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I5KRNAF.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I5N4CEF.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I62QPKU.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I68TME0.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I6ERYVL.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I6J199J.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I6TKJMW.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I6VWNNM.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I73RMKR.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I7AED4E.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I7F81H9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I7IUQ8A.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I7IYZBP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I8RZVVG.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I9VAMDI.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$I9XUZTA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IA82998.xls
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IAG31M9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IB74L41.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IBAXEBO.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IBEV0RJ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IBI4U84.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IBPAYLP.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IBZ53GE.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IC6F8J8.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IDMQRO6.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IE19WU1.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IEAQMRU.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IEAUCY8.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IEIJZGF.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IEO1LT0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IFW0LBA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IG72ITU.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IG888TG.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IG8W7TH.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IGBQXF7.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IHC7UN5.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IHZAJ6K.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$II7AZTV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IIHJ5E6.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IIV2DMP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IJ4UJ7G.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IJG24Y0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IJJQM4A.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IJMY09A.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IK23VYD.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IK2V84F.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IK574JJ.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IK6W8XS.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IKKSZQU.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IKNMFD3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IKT1UU0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IKU32BB.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IL2MSID.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ILCP3X1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ILJAH3O.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ILM1SVO
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ILP3EE9.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IM0AC45.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IM2O7CF.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IM6BUDY.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IM6WIKQ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMHAQ67.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMMA6SS.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMO3O79.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMOW52B.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMTWGXK.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IMWNHIT.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IN8WW66.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$INNXXJZ.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$INXC5Z9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IO28LOA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IO8S66U.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IOEDRU9.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IOY1Q5K.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IP036LV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IP25BE1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IPF0YVF.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IPTMT3L
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IPXCMX1.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IQDXOXY.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IQI33JN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IQMRZC0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IQOK8GH.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IRXT5E7.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IS1WVPV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ISS34RN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ISSFO1D.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ITFRCI5.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ITIBTXP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ITJQCE3.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IU5VYU3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IUBOT82.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IUP52WW.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IVGMTSY.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IVKN3MU.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IVULOIQ.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IW4RBOW.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IWAKS2L.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IWERP17.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IWFUU30.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IWGTFCW.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IWZQQK8.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IX0JGRG.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IXM161L.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IY3VL7V.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IYBUXMD.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IYWH16F.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IYWQP3K.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IZ2JS3M.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$IZPUGLK.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R01CN4Y.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R0C72V6.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R0EW9TN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R17KITF.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R1CXE6M.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R2800FM.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R2JT1O2.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R2X2IZ3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R2ZQTA4.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R2ZY6RA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R31IRZW.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R321IMU.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R3EA3H7.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R3FTU8H.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R4GH78E.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R4U9GJS.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R5AQOZZ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R5GPS1R.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R5KRNAF.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R5N4CEF.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R62QPKU.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R68TME0.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R6J199J.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R6TKJMW.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R6VWNNM.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R73RMKR.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R7AED4E.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R7F81H9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R7IUQ8A.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R7IYZBP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R8RZVVG.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R9XUZTA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RA82998.xls
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RAG31M9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RB74L41.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RBAXEBO.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RBEV0RJ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RBI4U84.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RBPAYLP.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RBZ53GE.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RC6F8J8.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RDMQRO6.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RE19WU1.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$REAQMRU.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$REAUCY8.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$REIJZGF.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$REO1LT0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RFW0LBA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RG72ITU.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RG888TG.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RG8W7TH.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RGBQXF7.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RHC7UN5.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RHZAJ6K.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RI7AZTV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RIHJ5E6.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RIV2DMP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RJ4UJ7G.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RJG24Y0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RJJQM4A.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RJMY09A.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RK23VYD.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RK2V84F.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RK574JJ.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RK6W8XS.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RKKSZQU.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RKNMFD3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RKT1UU0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RKU32BB.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RL2MSID.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLCP3X1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLJAH3O.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLP3EE9.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RM0AC45.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RM2O7CF.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RM6BUDY.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RM6WIKQ.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMHAQ67.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMMA6SS.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMO3O79.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMOW52B.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMTWGXK.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RMWNHIT.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RN8WW66.lnk
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RNNXXJZ.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RNXC5Z9.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RO28LOA.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RO8S66U.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ROEDRU9.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$ROY1Q5K.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RP036LV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RP25BE1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPF0YVF.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPTMT3L
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPXCMX1.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RQDXOXY.zip
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RQI33JN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RQMRZC0.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RQOK8GH.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RRXT5E7.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RS1WVPV.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RSS34RN.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RSSFO1D.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RTFRCI5.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RTIBTXP.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RTJQCE3.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RU5VYU3.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RUBOT82.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RUP52WW.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RVGMTSY.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RVKN3MU.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RVULOIQ.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RW4RBOW.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RWAKS2L.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RWERP17.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RWFUU30.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RWGTFCW.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RWZQQK8.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RX0JGRG.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RXM161L.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RY3VL7V.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RYBUXMD.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RYWH16F.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RYWQP3K.gz
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RZ2JS3M.spn
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RZPUGLK.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\desktop.ini
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\CC_CLND_030000_000001_I_202511280000_1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\Eligible HW UPLOAD Securities and Corporate Bonds for DEC 2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\MTF_Approved_DEC_28112025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$R40JXV9\SettlementMaster_ICCL_CM_0_0_0_20251200_0_0000.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\AGEING_666100043_08082025100044.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\AGEING_666112042_04092025112044.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\CC_CLND_030000_000001_I_202508010000_1.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF MARGIN SHORTFALL 03-11-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF MARGIN SHORTFALL 04-11-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF MARGIN SHORTFALL 06-11-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF Margin Shortfall 07-11-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF MARGIN SHORTFALL 25.08.2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Copy of MTF MARGIN SHORTFALL 31-10-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF AGEING_666095933_17092025095934.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF AGEING_666113601_10092025113601.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF MARGIN SHORTFALL 04-12-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF MARGIN SHORTFALL 10-11-2025.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666073331_02122025073332.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666095918_09072025095919.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666100053_29102025100054.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666101340_17112025101340.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666111751_10072025111752.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666113952_24112025113954.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _AGEING_666114040_20102025114040.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _STOCK_RMS_17092025_10002372577699109870.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _STOCK_RMS_18112025_10022318247442764842.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF _STOCK_RMS_23102025_12443833394538580208.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_ AGEING_666095822_18072025095824.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666071141_17122025071143.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666071543_24122025071545.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666071610_11122025071611.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666071704_10122025071704.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666071929_15122025071929.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666072100_16122025072101.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666072522_08122025072523.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666072522_08122025072523.xlsx
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666072709_03122025072710.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666073007_23122025073008.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666073238_22122025073239.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666080506_27112025080507.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666083905_26112025083906.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666084507_21082025084507.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666084925_05082025084926.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666090518_01092025090519.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666091114_29082025091115.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666091409_31072025091410.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666092057_16092025092058.xls.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666093142_09092025093144.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666093808_03092025093808.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666094438_20082025094439.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666094610_30072025094611.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666094919_18092025094920.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666095100_25082025095101.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666095803_22092025095804.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100107_12082025100110.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100128_18112025100129.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100316_04112025100316.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100431_11082025100432.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100500_04082025100501.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100529_18082025100530.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666100746_11112025100746.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101045_16102025101048.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101131_07082025101132.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101216_23072025101217.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101317_15092025101318.xls.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101636_06112025101637.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666101718_28072025101720.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666102556_07112025102557.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666103009_25072025103010.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666105207_17072025105208.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666105339_14112025105340.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666105532_25112025105532.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666105652_11072025105653.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110310_24072025110311.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110333_14082025110334.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110412_14072025110413.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110507_13082025110508.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110621_02092025110622.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110711_15072025110712.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666110953_22082025110955.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666111209_22072025111210.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666111219_05092025111220.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\mtf_ageing_666111330_22042025111331.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666111431_21072025111432.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666111822_06082025111823.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666111932_19082025111933.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666112155_12092025112156.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666112934_13112025112935.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666112936_28102025112937.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666113048_01082025113048.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666113318_12112025113319.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666113345_23092025113346.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666114401_03112025114401.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666114437_27102025114438.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666115300_17102025115301.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666115628_13102025115629.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666121111_26092025121111.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666121849_15102025121850.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666121856_10102025121857.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666124344_23102025124344.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666130014_14102025130015.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666130420_19092025130421.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGEING_666130740_25092025130741.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_AGING_666100933_10112025100933.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STCOK_RMS_11072025_1057353923475681527.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_1000112_RMS_02092025_11081161749071027976.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_01082025_1131348792068335062.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_01092025_09061798339521717187.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_01122025_07283054808528822429.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_02122025_07341053320497732452.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_03092025_09385410293144724367.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_03112025_1144486858602431277.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_03122025_07275138346447212647.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_04082025_10055678015111502723.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_04092025_1121291529630437267.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_05082025_08500520574648937972.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_05092025_11131594426162746903.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_06082025_11190129080013641100.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_06112025_10171926483099857669.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_07082025_10121198650142888383.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_07112025_10263555578737045456.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_08082025_10015932486383102910.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_09072025_10001139954459843216.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_09092025_0932306634895048448.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_10072025_11183586747716834731.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_10092025_11365313285777504765.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_10102025_12194962708148518527.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_10112025_1010357768867749070.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_10122025_07174120001796964080.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_11082025_10052892371405605677.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_11112025_10085377143875586937.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_11122025_07164712302115205566.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_12092025_11230342024591507058.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_12112025_11340692378007631410.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_13082025_11063736088396976881.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_13102025_11571258850821138544.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_13112025_11302011091892968389.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_14072025_1106208394750551491.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_14082025_11041995309855641374.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_14102025_01073870449045519966.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_14112025_10542710811328210349.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_15072025_11081396010535517818.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_15102025_12193426732672473185.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_15122025_07210321563926143460.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_16092025_0921468175928422356.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_16102025_10114170286744411406.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_16122025_07220340085778337380.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_17072025_1052539212271587780.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_17102025_11563569621509478473.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_17112025_10142114110497565705.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_17122025_07122241940611997975.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_18072025_0959519536783110055.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_18082025_1006269649024237212.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_18092025_09501840640142875235.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_19082025_11203693780448276828.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_19092025_0105431938687752221.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_20082025_09453366011487052561.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_20102025_11412337177503681156.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_21072025_1115191323952164213.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_21082025_08455336681886506517.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_22072025_11125051157761116544.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_22082025_1110521920861558657.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_22092025_1005261266550748887.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_22122025_07334843252486004400.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_23072025_10130112979699060202.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_23092025_11573319696991413066.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_24072025_11040491231029049485.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_24112025_11404867873772713344.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_24122025_07163652322882326853.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_25072025_10305724198533490752.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_25082025_09514695223992867856.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_25092025_01105268407598644292.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_25112025_10561424885283367177.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_26092025_12115128381955487020.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_26112025_08402781935575131413.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_27102025_11455777140307404689.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_27112025_08171360385457987182.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_28072025_11014337954219173982.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_28102025_11301937653102774470.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_29082025_09120195829867781262.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_29102025_10013779950563529641.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_30072025_09484750209965499719.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_30102025_1155026865196317366.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK_RMS_31072025_09151039792766917650.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK__RMS_04112025_10050558165967419941.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK__RMS_08122025_07261556772778539101.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK__RMS_12082025_11171525697036136182.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK__RMS_15092025_10140532940586435179.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\MTF_STOCK__RMS_23122025_07304284712727709415.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\SettlementMaster_ICCL_CM_0_0_0_20250800_0_0000.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RLM1SVO\Stock_ageingxlsx_1000112_RMS_22042025_11143546567076905921.csv
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPTMT3L\.
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPTMT3L\..
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPTMT3L\EQ_MGDTLS_MGTM_0408_19122025_05.CSV
C:\\$Recycle.Bin\\S-1-5-21-3119273522-2427777209-1705870880-500\$RPTMT3L\EQ_SHRTCOLL_0408_19122025.CSV
92430 - Registry Editor Last Accessed
-
Synopsis
Nessus was able to find the last key accessed by the Registry Editor when it was closed on the remote host.
Description
Nessus was able to find evidence of the last key that was opened when the Registry Editor was closed for each user.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Production
- Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

10940 - Remote Desktop Protocol Service Detection
-
Synopsis
The remote host has an remote desktop protocol service enabled.
Description
The Remote Desktop Protocol allows a user to remotely obtain a graphical login (and therefore act as a local user on the remote host).

If an attacker gains a valid login and password, this service could be used to gain further access on the remote host. An attacker may also use this service to mount a dictionary attack against the remote host to try to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimate users by impersonating the Windows server.
Solution
Disable the service if you do not use it, and do not allow this service to run across the Internet.
Risk Factor
None
Plugin Information
Published: 2002/04/20, Modified: 2023/08/21
Plugin Output

tcp/3389/msrdp

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/1433/mssql

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/3389/msrdp

The target TLS server offers no post-quantum ciphers.

277650 - Remote Services Not Using Post-Quantum Ciphers
-
Synopsis
Reports remote services that do not offer post-quantum ciphers.
Description
This plugin reports network services that do not offer post-quantum ciphers. Tenable makes no attempt to determine whether the remote service would be vulnerable to a post-quantum attack.

However, cryptography that depends on the classic difficulty of solving the discrete logarithm problem or on the classic difficulty of large prime factorization is broken by Shor's algorithm. Examples of this are RSA asymmetric encryption and Diffie-Hellman key exchange.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/08
Plugin Output

tcp/51528/www

The target TLS server offers no post-quantum ciphers.

62042 - SMB QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote host has quick-fix engineering updates installed.
Description
By connecting to the host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/09/11, Modified: 2022/02/01
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

KB4048953, Installed on: 2018/02/03
KB4049065, Installed on: 2018/02/03
KB4054590, Installed on: 2024/06/06
KB4103720, Installed on: 2024/05/31
KB5012170
KB5037016, Installed on: 2024/05/31
KB5037763
42897 - SMB Registry : Start the Registry Service during the scan (WMI)
-
Synopsis
The registry service was enabled for the duration of the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down, this plugin will attempt to start for the duration of the scan.

For this plugin to work, you need to select the option 'Start the Remote Registry service during the scan' on the credentials page when you add your Windows credentials.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully started for the duration of the scan.
42898 - SMB Registry : Stop the Registry Service after the scan (WMI)
-
Synopsis
The registry service was stopped after the scan.
Description
To perform a full credentialed scan, Nessus needs the ability to connect to the remote registry service (RemoteRegistry). If the service is down and if Nessus automatically enabled the registry for the duration of the scan, this plugins will stop it afterwards.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/11/25, Modified: 2025/12/15
Plugin Output

tcp/0


The registry service was successfully stopped after the scan.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/1433/mssql


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/3389/msrdp


This port supports TLSv1.0/TLSv1.1/TLSv1.2.

56984 - SSL / TLS Versions Supported
-
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2025/06/16
Plugin Output

tcp/51528/www


This port supports TLSv1.3/TLSv1.2.

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


The host name known by Nessus is :

xhwakeyesrv

The Common Name in the certificate is :

ssl_self_signed_fallback

45410 - SSL Certificate 'commonName' Mismatch
-
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output

tcp/51528/www


The host name known by Nessus is :

xhwakeyesrv

The Common Name in the certificate is :

www.lkp.net.in

The Subject Alternate Names in the certificate are :

admin.pennypal.in
aims.lkp.net.in
allocation.lkp.net.in
api.lkp.net.in
backoffice.lkp.net.in
bo.lkp.net.in
demo.pennypal.in
devtrade.lkp.net.in
devtradekyc.lkp.net.in
druat.pennypal.in
ekyc.lkp.net.in
ekyc.lkponline.com
ekyc.pennypal.in
ekycuat.lkp.net.in
getsetgrow.lkponline.com
hrms.lkp.net.in
ia.lkp.net.in
ipo.lkp.net.in
lkp.net.in
lkpconnect.net.in
lkpsec.com
lms.lkp.net.in
middleware.lkp.net.in
middlewareapi.lkp.net.in
notification.lkponline.com
notification.pennypal.in
pay.lkp.net.in
pennypal.in
ra.lkp.net.in
referral.pennypal.in
rekyc.pennypal.in
spip.lkp.net.in
spip.lkponline.com
trading.lkponline.com
trading.pennypal.in
trilogy.lkp.net.in
uat.lkp.net.in
uat.lkpsec.com
uat.pennypal.in
uatbackoffice.lkp.net.in
uatekyc.lkponline.com
uatgetsetgrow.lkponline.com
uatspip.lkponline.com
uattrading.lkponline.com
uatweb.pennypal.in
wealth.lkp.net.in
welcome.lkp.net.in
www.lkp.net.in
www.lkpfinance.com
www.lkpsec.com

83298 - SSL Certificate Chain Contains Certificates Expiring Soon
-
Synopsis
The remote host has an SSL certificate chain with one or more certificates that are going to expire soon.
Description
The remote host has an SSL certificate chain with one or more SSL certificates that are going to expire soon. Failure to renew these certificates before the expiration date may result in denial of service for users.
Solution
Renew any soon to expire SSL certificates.
Risk Factor
None
Plugin Information
Published: 2015/05/08, Modified: 2015/05/08
Plugin Output

tcp/3389/msrdp


The following soon to expire certificate was part of the certificate
chain sent by the remote host :

|-Subject : CN=XHwakEyeSrv
|-Not After : Mar 04 01:34:30 2026 GMT
42981 - SSL Certificate Expiry - Future Expiry
-
Synopsis
The SSL certificate associated with the remote service will expire soon.
Description
The SSL certificate associated with the remote service will expire soon.
Solution
Purchase or generate a new SSL certificate in the near future to replace the existing one.
Risk Factor
None
Plugin Information
Published: 2009/12/02, Modified: 2020/09/04
Plugin Output

tcp/3389/msrdp


The SSL certificate will expire within 60 days, at
Mar 4 01:34:30 2026 GMT :

Subject : CN=XHwakEyeSrv
Issuer : CN=XHwakEyeSrv
Not valid before : Sep 2 01:34:30 2025 GMT
Not valid after : Mar 4 01:34:30 2026 GMT

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql

Subject Name:

Common Name: SSL_Self_Signed_Fallback

Issuer Name:

Common Name: SSL_Self_Signed_Fallback

Serial Number: 76 B1 4A E7 D1 06 80 A2 4A 86 82 7A 7E EF 3F 3B

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Jan 05 01:30:48 2026 GMT
Not Valid After: Jan 05 01:30:48 2056 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 B1 46 55 AC 4A 9E 3F 96 68 7D CF 9D B1 AF D2 64 BD CE E5
51 69 05 4C 11 AB C8 15 9F C9 4C 02 DB 76 DA 84 69 92 3E A0
15 AA 39 EF F6 7C 2C 4C 55 2E FD 5E 30 75 A6 64 31 5F 1F E4
2F 38 E5 F1 B6 08 93 74 7D AA 94 94 97 14 F7 B2 7C D6 6F 03
A7 49 DB F3 05 99 2F 80 4C 0F 5F 7B 7D 9C E4 6F 20 F0 FB A0
F4 76 22 3A 01 C3 0E 00 F5 70 E3 73 3E F3 1A 45 E2 62 9B 60
43 FB AA E5 A3 A0 5D F9 77 3E A3 20 08 BE 26 06 99 D0 3A 98
69 4C 87 02 11 D4 9B 97 82 5C 22 E3 84 3A 08 9F 75 8E DE 15
6E 07 6B 84 8B 26 3C 20 03 A1 13 CC 98 1F 7F 63 73 B1 A8 B0
3A F5 E5 0E 87 10 36 E9 7E 43 6E 97 E9 DA 97 F0 17 3C 7D 1A
A1 F5 AF 3E 4D 75 54 F7 88 A3 D4 AF 19 9A 12 8B B4 63 73 D7
2E 7A BB D4 BC 2F B8 2D 1C 01 AE 81 4B 37 76 75 28 89 4D 03
19 C2 0D 52 B2 C2 78 A3 74 C0 F3 35 62 65 CC BC 07
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 74 36 D8 95 D2 BF 64 8A F3 28 07 63 4F E9 8B DA 97 FB 9A
27 39 D6 DA A1 3E 31 D9 2B 02 F4 3F F4 0B B0 25 72 67 2F F5
0F 87 1A 05 56 E8 51 3D B1 A8 D1 82 E9 C7 88 BC 53 57 DD 3C
4C AB E8 F9 C1 3F BE DA BC 23 F5 0B AC F3 FF 31 6B 9B FA 3B
97 5F A0 56 1B 38 7C 1F 49 61 32 70 D8 DE 2E CA E7 11 82 2B
4D D1 C6 D0 EC 77 94 A6 F2 EE 33 30 BC A0 B7 4D 62 AA E1 EB
C8 AF B1 C1 2F 77 95 93 72 ED 0B 76 7C 28 95 C0 29 56 DC FE
4A F3 5D BD 35 7A 12 E1 6A 63 43 69 A8 81 FD C9 68 A1 E6 47
82 5C 73 5D 58 7E BF C4 50 C2 51 00 C1 7F 6D E8 53 EA 8D FF
2E F2 3C C2 D0 7B 62 C7 BC AA 88 3D B6 93 68 65 AC 1C 36 86
8F BD EA 45 F8 12 C3 E6 D0 2B 38 64 C6 F0 DA A4 EC 19 08 DB
A8 17 4B 15 39 B3 B6 D4 5D B0 82 60 9F 16 3E E9 ED 43 B7 69
E5 F2 E4 10 6E B9 DB F8 79 E9 A7 1B 31 35 8F BC A0

Fingerprints :

SHA-256 Fingerprint: AF 0F 22 99 CC 1F 4F 55 27 14 2A 69 B4 37 05 CF 9E 23 AA DC
70 8D 73 86 93 92 18 8B 23 AF E4 44
SHA-1 Fingerprint: 74 C7 C0 EE 8F D3 84 43 54 32 85 BA 6C 68 BD 43 D3 5A CB 82
MD5 Fingerprint: 7D 32 6A B7 13 9B B8 A4 C3 D1 F4 02 BC FC A3 58


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIDADCCAeigAwIBAgIQdrFK59EGgKJKhoJ6fu8/OzANBgkqhkiG9w0BAQsFADA7MTkwNwYDVQQDHjAAUwBTAEwAXwBTAGUAbABmAF8AUwBpAGcAbgBlAGQAXwBGAGEAbABsAGIAYQBjAGswIBcNMjYwMTA1MDEzMDQ4WhgPMjA1NjAxMDUwMTMwNDhaMDsxOTA3BgNVBAMeMABTAFMATABfAFMAZQBsAGYAXwBTAGkAZwBuAGUAZABfAEYAYQBsAGwAYgBhAGMAazCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALFGVaxKnj+WaH3PnbGv0mS9zuVRaQVMEavIFZ/JTALbdtqEaZI+oBWqOe/2fCxMVS79XjB1pmQxXx/kLzjl8bYIk3R9qpSUlxT3snzWbwOnSdvzBZkvgEwPX3t9nORvIPD7oPR2IjoBww4A9XDjcz7zGkXiYptgQ/uq5aOgXfl3PqMgCL4mBpnQOphpTIcCEdSbl4JcIuOEOgifdY7eFW4Ha4SLJjwgA6ETzJgff2NzsaiwOvXlDocQNul+Q26X6dqX8Bc8fRqh9a8+TXVU94ij1K8ZmhKLtGNz1y56u9S8L7gtHAGugUs3dnUoiU0DGcINUrLCeKN0wPM1YmXMvAcCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAdDbYldK/ZIrzKAdjT+mL2pf7mic51tqhPjHZKwL0P/QLsCVyZy/1D4caBVboUT2xqNGC6ceIvFNX3TxMq+j5wT++2rwj9Qus8/8xa5v6O5dfoFYbOHwfSWEycNjeLsrnEYIrTdHG0Ox3lKby7jMwvKC3TWKq4evIr7HBL3eVk3LtC3Z8KJXAKVbc/krzXb01ehLhamNDaaiB/clooeZHglxzXVh+v8RQwlEAwX9t6FPqjf8u8jzC0Htix7yqiD22k2hlrBw2ho+96kX4EsPm0Cs4ZMbw2qTsGQjbqBdLFTmzttRdsIJgnxY+6e1Dt2nl8uQQbrnb+HnppxsxNY+8oA==
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: XHwakEyeSrv

Issuer Name:

Common Name: XHwakEyeSrv

Serial Number: 1E 62 3B DA 42 5F 32 BF 49 3F E3 13 B5 71 AB 77

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 02 01:34:30 2025 GMT
Not Valid After: Mar 04 01:34:30 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 AB 9A 14 0E 05 28 43 0B D5 DC E4 C2 88 B4 A3 76 A3 27 41
8E D8 DB 28 65 53 A8 92 56 D1 BF 41 47 EE 0B D2 B9 E3 E1 DF
76 A6 8A 22 A5 1A 72 BA D4 D1 30 38 23 77 62 A2 6E 69 00 A6
33 23 F2 27 51 6E 59 58 BA CC 25 9D 09 E7 9F EA 49 30 C1 9D
F6 92 CC 4C 2B F6 F9 AC 80 B1 D4 92 2A 3F 48 4D ED AF 4D 5C
0A 2B AE 21 57 1E B8 69 12 C1 79 97 35 AD 5B A0 23 14 3F 66
08 D7 4D 56 1D C2 D2 D1 BF 49 5C D1 EA 2E 96 27 32 8B F7 77
63 2A 13 EA 36 1A 36 98 2E 4B A8 7A 63 2E 47 BF 83 9C 44 7D
5F 71 AF C3 DF 03 C8 38 CE 25 E0 49 DF 9B 72 46 04 11 4B 0F
BC 35 85 B5 54 C4 14 83 F0 B0 E7 E3 21 AB 45 AB B1 99 E1 C4
1C D5 3F 07 CA 2D 4C CF F4 E6 8E DE E1 29 6C FE A3 46 56 D8
5A 8B E9 C5 B9 FF 3B 4B CA D4 1A 1F 3E DD AE 8B 80 0A A7 AA
8C F4 E7 15 98 FC A5 E3 4D 1F 50 E0 C6 61 3B 6E 43
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 7F 95 AB F2 92 FC 45 01 F1 FE E3 92 D5 B3 E7 2F 17 98 A3
D5 CF 22 DD A2 5B 47 61 FC E5 93 DB FC C7 5F D4 25 8C CC 36
27 F3 E8 24 4F B5 ED 48 AD 18 A3 0A 70 03 E7 E3 59 09 74 C0
29 0B 41 60 B3 6A 1C 4D 64 42 40 AF 4D D9 9B B9 3B D0 D3 F6
8F 62 D5 73 41 59 6F 9F 6E D6 33 48 FB F9 7C E6 22 42 6E 18
F2 01 77 BA B9 D6 06 2D 03 46 F4 0A C8 B1 A1 80 79 60 F6 DE
6E 95 53 AA AA E2 4F 83 9D 0B 44 D1 0D ED 7A AC AC 64 36 29
9F 41 08 2D FD 71 6F F7 42 23 D7 B4 51 51 7F 17 2E 5D EB 7D
D7 C3 BE 2A 4A C2 9F 67 53 98 6A 32 CB 6A F0 78 5F 0E DB A4
82 13 6D 4F FC 90 45 A8 8A 6F B9 FD E8 A5 34 2D B6 C8 0E DD
D9 A2 97 40 B9 32 B2 C0 38 D5 1B 4A 5F 08 82 D3 34 D6 BA 73
3B F6 A4 0D 4C A8 EA 72 93 50 E8 13 41 CD D1 F0 D7 1F 74 CA
91 9F E3 73 16 5B 0A 53 57 AC 89 7C D8 08 D5 DB 1B

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment


Fingerprints :

SHA-256 Fingerprint: A2 B9 59 04 9E BF 98 82 75 E7 5E E6 BD B2 A3 C8 AE 08 32 EA
49 A5 7A 6D 6C 5A B1 81 F9 0E 27 C2
SHA-1 Fingerprint: 6E 0F 63 BE E9 49 8A 2B 92 26 D0 4D 86 75 25 EE A7 1B 4F DE
MD5 Fingerprint: 2F 64 BD 0C 91 D8 B0 C0 2F 08 E0 9F D6 8B 94 41


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIC2jCCAcKgAwIBAgIQHmI72kJfMr9JP+MTtXGrdzANBgkqhkiG9w0BAQsFADAWMRQwEgYDVQQDEwtYSHdha0V5ZVNydjAeFw0yNTA5MDIwMTM0MzBaFw0yNjAzMDQwMTM0MzBaMBYxFDASBgNVBAMTC1hId2FrRXllU3J2MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq5oUDgUoQwvV3OTCiLSjdqMnQY7Y2yhlU6iSVtG/QUfuC9K54+HfdqaKIqUacrrU0TA4I3diom5pAKYzI/InUW5ZWLrMJZ0J55/qSTDBnfaSzEwr9vmsgLHUkio/SE3tr01cCiuuIVceuGkSwXmXNa1boCMUP2YI101WHcLS0b9JXNHqLpYnMov3d2MqE+o2GjaYLkuoemMuR7+DnER9X3Gvw98DyDjOJeBJ35tyRgQRSw+8NYW1VMQUg/Cw5+Mhq0WrsZnhxBzVPwfKLUzP9OaO3uEpbP6jRlbYWovpxbn/O0vK1BofPt2ui4AKp6qM9OcVmPyl400fUODGYTtuQwIDAQABoyQwIjATBgNVHSUEDDAKBggrBgEFBQcDATALBgNVHQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBAH+Vq/KS/EUB8f7jktWz5y8XmKPVzyLdoltHYfzlk9v8x1/UJYzMNifz6CRPte1IrRijCnAD5+NZCXTAKQtBYLNqHE1kQkCvTdmbuTvQ0/aPYtVzQVlvn27WM0j7+XzmIkJuGPIBd7q51gYtA0b0CsixoYB5YPbebpVTqqriT4OdC0TRDe16rKxkNimfQQgt/XFv90Ij17RRUX8XLl3rfdfDvipKwp9nU5hqMstq8HhfDtukghNtT/yQRaiKb7n96KU0LbbIDt3ZopdAuTKywDjVG0pfCILTNNa6czv2pA1MqOpyk1DoE0HN0fDXH3TKkZ/jcxZbClNXrIl82AjV2xs=
-----END CERTIFICATE-----

10863 - SSL Certificate Information
-
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output

tcp/51528/www

Subject Name:

Country: IN
State/Province: Maharashtra
Locality: Mumbai
Organization: LKP SECURITIES LIMITED
Common Name: www.lkp.net.in

Issuer Name:

Country: BE
Organization: GlobalSign nv-sa
Common Name: GlobalSign RSA OV SSL CA 2018

Serial Number: 19 A0 03 FE 47 ED 49 8F 58 AA 19 0A

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Apr 21 10:26:13 2025 GMT
Not Valid After: May 23 10:26:12 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 BF AD CA E4 8E 7F CA 0A 53 22 21 11 61 2F 16 AB A2 1E E1
8C F4 D4 F3 FE BF 71 33 7F E4 DA 14 0C D4 1A 94 23 D5 D8 84
8C F3 88 52 5B E9 16 F0 11 2A 6A 1D C1 04 EE AA 58 0B 41 03
0E 5E E7 E3 7D 19 BF 94 72 12 36 70 3C F8 70 C8 64 98 2E 2D
18 00 93 7E 42 10 0F 11 5A F3 B0 73 8A E6 D2 9B 42 1E 0A A8
25 3B 7E 3D D6 D0 80 D7 47 2D 35 1F BA D1 D0 9A 6E 77 AC BD
95 49 5C 70 61 9A 77 20 EB 41 1B 0E 37 24 59 10 00 FA B7 EF
16 31 13 78 86 6E 73 7B 4C 5F C6 A0 71 97 25 90 24 B2 87 4B
45 E7 D9 5D C7 17 59 01 D8 94 F2 5A 95 BC 3F 3D EC 48 9E 23
B2 B3 7C 71 FB 50 E6 7B 59 F2 3C 02 FB 0C 54 7E 05 05 A8 97
57 69 05 BB 6B DF 05 15 4D EC 4A DC 99 05 A0 64 C5 76 54 7A
C4 31 92 0E 43 D1 53 88 2A ED 81 CD 44 A6 DA 1F 80 55 11 84
EF 92 27 43 DB E2 D4 71 A6 B4 95 1F 35 15 EB 61 8B
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 70 EA 52 F8 6C 82 4B 72 5D FA 42 2E A6 FF 47 33 0B 5E 2F
BF 71 9E 0F C7 F6 17 B4 5C 29 2C BB 72 26 53 6C 4A EA E7 EF
C0 31 95 6A 51 D6 2A A5 9C 99 0C 7B 8E BE 4B 10 4C B6 20 65
91 36 C7 FE 70 7B 31 11 11 A3 02 CD 2D DA 59 46 FA 32 23 73
9D BF AE 3C 9A A0 ED E8 40 EE 96 FB 64 9C 94 03 16 58 C2 21
69 2E 74 44 3F 05 BC 2D A4 E1 A1 11 77 17 10 FC 8A E2 E6 18
E1 25 E4 43 A3 78 38 EB D0 96 85 2C 8D 72 ED 68 15 7F 90 C1
62 DF A9 F1 5C DD 87 84 9C 33 23 1C F2 51 08 C2 AC 17 84 85
F8 F7 93 AB 17 6E 32 D0 DF 2B 69 4A 32 68 6A 53 27 AF C3 5F
4B 7A F0 31 3E CB 4F 48 20 3E 06 D2 3B 0C 65 B4 63 3B D2 7B
45 DC 5B 33 40 97 33 CC 31 99 24 80 E3 C1 F6 C4 5F C6 B0 DC
54 82 A8 01 E7 4F AD 58 5A 1D B1 25 01 1A C3 84 19 EB 32 E7
20 79 07 E6 06 DD EE 28 DC 63 03 7D 2A 90 2C 6E C7

Extension: Key Usage(2.5.29.15)
Critical: 1
Key Usage: Digital Signature, Key Encipherment


Extension: Basic Constraints(2.5.29.19)
Critical: 1


Extension: Authority Information Access(1.3.6.1.5.5.7.1.1)
Critical: 0
Method#1: Certificate Authority Issuers
URI: http://secure.globalsign.com/cacert/gsrsaovsslca2018.crt
Method#2: Online Certificate Status Protocol
URI: http://ocsp.globalsign.com/gsrsaovsslca2018


Extension: Policies(2.5.29.32)
Critical: 0
Policy ID #1: 1.3.6.1.4.1.4146.1.20
Qualifier ID #1: Certification Practice Statement(1.3.6.1.5.5.7.2.1)
CPS URI: https://www.globalsign.com/repository/
Policy ID #2: 2.23.140.1.2.2


Extension: Subject Alternative Name(2.5.29.17)
Critical: 0
DNS: www.lkp.net.in
DNS: www.lkpfinance.com
DNS: uattrading.lkponline.com
DNS: www.lkpsec.com
DNS: trading.lkponline.com
DNS: ekyc.lkponline.com
DNS: lkpsec.com
DNS: uatekyc.lkponline.com
DNS: uat.lkpsec.com
DNS: trading.pennypal.in
DNS: ekyc.pennypal.in
DNS: rekyc.pennypal.in
DNS: uat.pennypal.in
DNS: uatweb.pennypal.in
DNS: pennypal.in
DNS: demo.pennypal.in
DNS: referral.pennypal.in
DNS: notification.lkponline.com
DNS: notification.pennypal.in
DNS: admin.pennypal.in
DNS: uatspip.lkponline.com
DNS: spip.lkponline.com
DNS: druat.pennypal.in
DNS: uatgetsetgrow.lkponline.com
DNS: getsetgrow.lkponline.com
DNS: lkpconnect.net.in
DNS: pay.lkp.net.in
DNS: ekyc.lkp.net.in
DNS: bo.lkp.net.in
DNS: lms.lkp.net.in
DNS: ia.lkp.net.in
DNS: welcome.lkp.net.in
DNS: hrms.lkp.net.in
DNS: devtrade.lkp.net.in
DNS: api.lkp.net.in
DNS: aims.lkp.net.in
DNS: backoffice.lkp.net.in
DNS: devtradekyc.lkp.net.in
DNS: spip.lkp.net.in
DNS: ekycuat.lkp.net.in
DNS: uatbackoffice.lkp.net.in
DNS: wealth.lkp.net.in
DNS: middleware.lkp.net.in
DNS: middlewareapi.lkp.net.in
DNS: ra.lkp.net.in
DNS: ipo.lkp.net.in
DNS: uat.lkp.net.in
DNS: allocation.lkp.net.in
DNS: trilogy.lkp.net.in
DNS: lkp.net.in


Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)
Purpose#2: Web Client Authentication (1.3.6.1.5.5.7.3.2)


Extension: Authority Key Identifier(2.5.29.35)
Critical: 0
Key Identifier: F8 EF 7F F2 CD 78 67 A8 DE 6F 8F 24 8D 88 F1 87 03 02 B3 EB


Extension: Subject Key Identifier(2.5.29.14)
Critical: 0
Subject Key Identifier: 2E 3D 70 B7 04 25 4A 71 43 B6 6A 6E 85 CA 4F 2C 22 95 28 A3


Extension: 1.3.6.1.4.1.11129.2.4.2
Critical: 0
Data: 04 82 01 69 01 67 00 77 00 64 11 C4 6C A4 12 EC A7 89 1C A2
02 2E 00 BC AB 4F 28 07 D4 1E 35 27 AB EA FE D5 03 C9 7D CD
F0 00 00 01 96 57 E2 69 18 00 00 04 03 00 48 30 46 02 21 00
96 52 8C B8 51 AA B8 D9 42 47 DA 1B FE 27 35 66 2E 2F F8 E8
5F DC 5C C5 C9 80 52 A6 E0 0D E2 84 02 21 00 A1 D6 C8 6D 7C
91 4E EA 19 E7 3D 42 7C 00 6E 97 16 76 1A 20 DB 3A 9A 4B D3
E5 D0 87 00 78 3A 4A 00 75 00 CB 38 F7 15 89 7C 84 A1 44 5F
5B C1 DD FB C9 6E F2 9A 59 CD 47 0A 69 05 85 B0 CB 14 C3 14
58 E7 00 00 01 96 57 E2 67 BA 00 00 04 03 00 46 30 44 02 20
5A 27 C8 01 9F C7 B0 9C D6 52 AB 0C 14 AF 20 CF 47 3B 13 05
66 9C 9C 76 64 D8 63 D2 B2 B2 21 9C 02 20 70 82 E8 32 4F 4C
7E 13 8E EB 91 4E 72 A3 56 7A B3 4F DC E4 F6 24 76 97 97 48
28 ED 03 B4 32 70 00 75 00 25 2F 94 C2 2B 29 E9 6E 9F 41 1A
72 07 2B 69 5C 5B 52 FF 97 A9 0D 25 40 BB FC DC 51 EC 4D EE
0B 00 00 01 96 57 E2 69 53 00 00 04 03 00 46 30 44 02 20 61
5F F2 11 43 94 22 D8 EF 61 0C 44 F3 DE 58 50 0D D1 77 D4 45
F8 61 0A B0 3E 5C EA 8D 8C 25 B4 02 20 50 92 96 1B 3F 90 B7
23 1E 26 ED 3F 40 B4 C4 D7 5B 31 4E D7 B7 8B 1E 05 6D DC 51
65 50 91 04 E4


Fingerprints :

SHA-256 Fingerprint: 19 95 B4 E0 56 30 03 B7 44 C1 47 DE DF 5F 1D 04 45 F1 E6 34
1C 37 B0 18 DE 2B 36 C0 83 16 2F F1
SHA-1 Fingerprint: F6 61 74 C5 D8 D4 F2 0E A9 93 12 6E CA 56 3E A9 08 17 2C 9B
MD5 Fingerprint: 76 94 5C 1D 4F B6 7A 66 12 A9 03 D7 C5 41 35 8A


PEM certificate :

-----BEGIN CERTIFICATE-----
MIIKFTCCCP2gAwIBAgIMGaAD/kftSY9YqhkKMA0GCSqGSIb3DQEBCwUAMFAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1HbG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yNTA0MjExMDI2MTNaFw0yNjA1MjMxMDI2MTJaMG4xCzAJBgNVBAYTAklOMRQwEgYDVQQIEwtNYWhhcmFzaHRyYTEPMA0GA1UEBxMGTXVtYmFpMR8wHQYDVQQKExZMS1AgU0VDVVJJVElFUyBMSU1JVEVEMRcwFQYDVQQDEw53d3cubGtwLm5ldC5pbjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL+tyuSOf8oKUyIhEWEvFquiHuGM9NTz/r9xM3/k2hQM1BqUI9XYhIzziFJb6RbwESpqHcEE7qpYC0EDDl7n430Zv5RyEjZwPPhwyGSYLi0YAJN+QhAPEVrzsHOK5tKbQh4KqCU7fj3W0IDXRy01H7rR0Jpud6y9lUlccGGadyDrQRsONyRZEAD6t+8WMRN4hm5ze0xfxqBxlyWQJLKHS0Xn2V3HF1kB2JTyWpW8Pz3sSJ4jsrN8cftQ5ntZ8jwC+wxUfgUFqJdXaQW7a98FFU3sStyZBaBkxXZUesQxkg5D0VOIKu2BzUSm2h+AVRGE75InQ9vi1HGmtJUfNRXrYYsCAwEAAaOCBs8wggbLMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMIGOBggrBgEFBQcBAQSBgTB/MEQGCCsGAQUFBzAChjhodHRwOi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9nc3JzYW92c3NsY2EyMDE4LmNydDA3BggrBgEFBQcwAYYraHR0cDovL29jc3AuZ2xvYmFsc2lnbi5jb20vZ3Nyc2FvdnNzbGNhMjAxODBWBgNVHSAETzBNMEEGCSsGAQQBoDIBFDA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBvc2l0b3J5LzAIBgZngQwBAgIwggPgBgNVHREEggPXMIID04IOd3d3LmxrcC5uZXQuaW6CEnd3dy5sa3BmaW5hbmNlLmNvbYIYdWF0dHJhZGluZy5sa3BvbmxpbmUuY29tgg53d3cubGtwc2VjLmNvbYIVdHJhZGluZy5sa3BvbmxpbmUuY29tghJla3ljLmxrcG9ubGluZS5jb22CCmxrcHNlYy5jb22CFXVhdGVreWMubGtwb25saW5lLmNvbYIOdWF0LmxrcHNlYy5jb22CE3RyYWRpbmcucGVubnlwYWwuaW6CEGVreWMucGVubnlwYWwuaW6CEXJla3ljLnBlbm55cGFsLmlugg91YXQucGVubnlwYWwuaW6CEnVhdHdlYi5wZW5ueXBhbC5pboILcGVubnlwYWwuaW6CEGRlbW8ucGVubnlwYWwuaW6CFHJlZmVycmFsLnBlbm55cGFsLmlughpub3RpZmljYXRpb24ubGtwb25saW5lLmNvbYIYbm90aWZpY2F0aW9uLnBlbm55cGFsLmlughFhZG1pbi5wZW5ueXBhbC5pboIVdWF0c3BpcC5sa3BvbmxpbmUuY29tghJzcGlwLmxrcG9ubGluZS5jb22CEWRydWF0LnBlbm55cGFsLmlught1YXRnZXRzZXRncm93LmxrcG9ubGluZS5jb22CGGdldHNldGdyb3cubGtwb25saW5lLmNvbYIRbGtwY29ubmVjdC5uZXQuaW6CDnBheS5sa3AubmV0Lmlugg9la3ljLmxrcC5uZXQuaW6CDWJvLmxrcC5uZXQuaW6CDmxtcy5sa3AubmV0Lmlugg1pYS5sa3AubmV0LmlughJ3ZWxjb21lLmxrcC5uZXQuaW6CD2hybXMubGtwLm5ldC5pboITZGV2dHJhZGUubGtwLm5ldC5pboIOYXBpLmxrcC5uZXQuaW6CD2FpbXMubGtwLm5ldC5pboIVYmFja29mZmljZS5sa3AubmV0LmlughZkZXZ0cmFkZWt5Yy5sa3AubmV0Lmlugg9zcGlwLmxrcC5uZXQuaW6CEmVreWN1YXQubGtwLm5ldC5pboIYdWF0YmFja29mZmljZS5sa3AubmV0LmlughF3ZWFsdGgubGtwLm5ldC5pboIVbWlkZGxld2FyZS5sa3AubmV0LmlughhtaWRkbGV3YXJlYXBpLmxrcC5uZXQuaW6CDXJhLmxrcC5uZXQuaW6CDmlwby5sa3AubmV0Lmlugg51YXQubGtwLm5ldC5pboIVYWxsb2NhdGlvbi5sa3AubmV0LmlughJ0cmlsb2d5LmxrcC5uZXQuaW6CCmxrcC5uZXQuaW4wHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB8GA1UdIwQYMBaAFPjvf/LNeGeo3m+PJI2I8YcDArPrMB0GA1UdDgQWBBQuPXC3BCVKcUO2am6Fyk8sIpUoozCCAX0GCisGAQQB1nkCBAIEggFtBIIBaQFnAHcAZBHEbKQS7KeJHKICLgC8q08oB9QeNSer6v7VA8l9zfAAAAGWV+JpGAAABAMASDBGAiEAllKMuFGquNlCR9ob/ic1Zi4v+Ohf3FzFyYBSpuAN4oQCIQCh1shtfJFO6hnnPUJ8AG6XFnYaINs6mkvT5dCHAHg6SgB1AMs49xWJfIShRF9bwd37yW7ymlnNRwppBYWwyxTDFFjnAAABllfiZ7oAAAQDAEYwRAIgWifIAZ/HsJzWUqsMFK8gz0c7EwVmnJx2ZNhj0rKyIZwCIHCC6DJPTH4TjuuRTnKjVnqzT9zk9iR2l5dIKO0DtDJwAHUAJS+Uwisp6W6fQRpyBytpXFtS/5epDSVAu/zcUexN7gsAAAGWV+JpUwAABAMARjBEAiBhX/IRQ5Qi2O9hDETz3lhQDdF31EX4YQqwPlzqjYwltAIgUJKWGz+QtyMeJu0/QLTE11sxTte3ix4FbdxRZVCRBOQwDQYJKoZIhvcNAQELBQADggEBAHDqUvhsgktyXfpCLqb/RzMLXi+/cZ4Px/YXtFwpLLtyJlNsSurn78AxlWpR1iqlnJkMe46+SxBMtiBlkTbH/nB7MRERowLNLdpZRvoyI3Odv648mqDt6EDulvtknJQDFljCIWkudEQ/BbwtpOGhEXcXEPyK4uYY4SXkQ6N4OOvQloUsjXLtaBV/kMFi36nxXN2HhJwzIxzyUQjCrBeEhfj3k6sXbjLQ3ytpSjJoalMnr8NfS3rwMT7LT0ggPgbSOwxltGM70ntF3FszQJczzDGZJIDjwfbEX8aw3FSCqAHnT61YWh2xJQEaw4QZ6zLnIHkH5gbd7ijcYwN9KpAsbsc=
-----END CERTIFICATE-----

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/1433/mssql


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/3389/msrdp


Here is the list of SSL CBC ciphers supported by the remote server :

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

70544 - SSL Cipher Block Chaining Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output

tcp/51528/www


Here is the list of SSL CBC ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
ECDHE-RSA-CAMELLIA-CBC-128 0xC0, 0x76 ECDHE RSA Camellia-CBC(128) SHA256
ECDHE-RSA-CAMELLIA-CBC-256 0xC0, 0x77 ECDHE RSA Camellia-CBC(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
DHE-RSA-CAMELLIA128-SHA 0x00, 0x45 DHE RSA Camellia-CBC(128) SHA1
DHE-RSA-CAMELLIA256-SHA 0x00, 0x88 DHE RSA Camellia-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
DHE-RSA-AES128-SHA256 0x00, 0x67 DHE RSA AES-CBC(128) SHA256
DHE-RSA-AES256-SHA256 0x00, 0x6B DHE RSA AES-CBC(256) SHA256
DHE-RSA-CAMELLIA128-SHA256 0x00, 0xBE DHE RSA Camellia-CBC(128) SHA256
DHE-RSA-CAMELLIA256-SHA256 0x00, 0xC4 DHE RSA Camellia-CBC(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/1433/mssql


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/3389/msrdp


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv12
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv11
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA


SSL Version : TLSv1
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.

21643 - SSL Cipher Suites Supported
-
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output

tcp/51528/www


Here is the list of SSL ciphers supported by the remote server :
Each group is reported per SSL Version.

SSL Version : TLSv13
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS_AES_256_GCM_SHA384 0x13, 0x02 - - AES-GCM(256) SHA384


SSL Version : TLSv12
High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES-128-CCM-AEAD 0xC0, 0x9E DHE RSA AES-CCM(128) SHA-256
DHE-RSA-AES-128-CCM8-AEAD 0xC0, 0xA2 DHE RSA AES-CCM8(128) SHA-256
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES-256-CCM-AEAD 0xC0, 0x9F DHE RSA AES-CCM(256) SHA-384
DHE-RSA-AES-256-CCM8-AEAD 0xC0, 0xA3 DHE RSA AES-CCM8(256) SHA-384
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
DHE-RSA-CHACHA20-POLY1305 0xCC, 0xAA DHE RSA ChaCha20-Poly1305(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-CAMELLIA-CBC-128 0xC0, 0x76 ECDHE RSA Camellia-CBC(128) SHA256
ECDHE-RSA-CAMELLIA-CBC-256 0xC0, 0x77 ECDHE RSA Camellia-CBC(256) SHA384
ECDHE-RSA-CHACHA20-POLY1305 0xCC, 0xA8 ECDHE RSA ChaCha20-Poly1305(256) SHA256
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
DHE-RSA-CAMELLIA128-SHA 0x00, 0x45 DHE RSA Camellia-CBC(128) SHA1
DHE-RSA-CAMELLIA256-SHA 0x00, 0x88 DHE RSA Camellia-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
DHE-RSA-AES128-SHA256 0x00, 0x67 DHE RSA AES-CBC(128) SHA256
DHE-RSA-AES256-SHA256 0x00, 0x6B DHE RSA AES-CBC(256) SHA256
DHE-RSA-CAMELLIA128-SHA256 0x00, 0xBE DHE RSA Camellia-CBC(128) SHA256
DHE-RSA-CAMELLIA256-SHA256 0x00, 0xC4 DHE RSA Camellia-CBC(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/1433/mssql


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/3389/msrdp


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

57041 - SSL Perfect Forward Secrecy Cipher Suites Supported
-
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output

tcp/51528/www


Here is the list of SSL PFS ciphers supported by the remote server :

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES-128-CCM-AEAD 0xC0, 0x9E DHE RSA AES-CCM(128) SHA-256
DHE-RSA-AES-128-CCM8-AEAD 0xC0, 0xA2 DHE RSA AES-CCM8(128) SHA-256
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES-256-CCM-AEAD 0xC0, 0x9F DHE RSA AES-CCM(256) SHA-384
DHE-RSA-AES-256-CCM8-AEAD 0xC0, 0xA3 DHE RSA AES-CCM8(256) SHA-384
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
DHE-RSA-CHACHA20-POLY1305 0xCC, 0xAA DHE RSA ChaCha20-Poly1305(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x2F ECDHE RSA AES-GCM(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x30 ECDHE RSA AES-GCM(256) SHA384
ECDHE-RSA-CAMELLIA-CBC-128 0xC0, 0x76 ECDHE RSA Camellia-CBC(128) SHA256
ECDHE-RSA-CAMELLIA-CBC-256 0xC0, 0x77 ECDHE RSA Camellia-CBC(256) SHA384
ECDHE-RSA-CHACHA20-POLY1305 0xCC, 0xA8 ECDHE RSA ChaCha20-Poly1305(256) SHA256
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
DHE-RSA-CAMELLIA128-SHA 0x00, 0x45 DHE RSA Camellia-CBC(128) SHA1
DHE-RSA-CAMELLIA256-SHA 0x00, 0x88 DHE RSA Camellia-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
DHE-RSA-AES128-SHA256 0x00, 0x67 DHE RSA AES-CBC(128) SHA256
DHE-RSA-AES256-SHA256 0x00, 0x6B DHE RSA AES-CBC(256) SHA256
DHE-RSA-CAMELLIA128-SHA256 0x00, 0xBE DHE RSA Camellia-CBC(128) SHA256
DHE-RSA-CAMELLIA256-SHA256 0x00, 0xC4 DHE RSA Camellia-CBC(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

51891 - SSL Session Resume Supported
-
Synopsis
The remote host allows resuming SSL sessions.
Description
This script detects whether a host allows resuming SSL sessions by performing a full SSL handshake to receive a session ID, and then reconnecting with the previously used session ID. If the server accepts the session ID in the second connection, the server maintains a cache of sessions that can be resumed.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/07, Modified: 2021/09/13
Plugin Output

tcp/1433/mssql


This port supports resuming TLSv1 / TLSv1 / TLSv1 sessions.

51891 - SSL Session Resume Supported
-
Synopsis
The remote host allows resuming SSL sessions.
Description
This script detects whether a host allows resuming SSL sessions by performing a full SSL handshake to receive a session ID, and then reconnecting with the previously used session ID. If the server accepts the session ID in the second connection, the server maintains a cache of sessions that can be resumed.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/07, Modified: 2021/09/13
Plugin Output

tcp/3389/msrdp


This port supports resuming TLSv1 / TLSv1 / TLSv1 sessions.

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/1433/mssql

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/3389/msrdp

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1

High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
RSA-AES128-SHA256 0x00, 0x9C RSA RSA AES-GCM(128) SHA256
RSA-AES256-SHA384 0x00, 0x9D RSA RSA AES-GCM(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
AES128-SHA 0x00, 0x2F RSA RSA AES-CBC(128) SHA1
AES256-SHA 0x00, 0x35 RSA RSA AES-CBC(256) SHA1
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384
RSA-AES128-SHA256 0x00, 0x3C RSA RSA AES-CBC(128) SHA256
RSA-AES256-SHA256 0x00, 0x3D RSA RSA AES-CBC(256) SHA256

Unrecognized Ciphers

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
TLS1_CK_RSA_WITH_RC4_128_MD5
TLS1_CK_RSA_WITH_RC4_128_SHA

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

156899 - SSL/TLS Recommended Cipher Suites
-
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:

TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256

TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305

This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or more) years.
See Also
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output

tcp/51528/www

The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:


High Strength Ciphers (>= 112-bit key)

Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DHE-RSA-AES-128-CCM-AEAD 0xC0, 0x9E DHE RSA AES-CCM(128) SHA-256
DHE-RSA-AES-128-CCM8-AEAD 0xC0, 0xA2 DHE RSA AES-CCM8(128) SHA-256
DHE-RSA-AES128-SHA256 0x00, 0x9E DHE RSA AES-GCM(128) SHA256
DHE-RSA-AES-256-CCM-AEAD 0xC0, 0x9F DHE RSA AES-CCM(256) SHA-384
DHE-RSA-AES-256-CCM8-AEAD 0xC0, 0xA3 DHE RSA AES-CCM8(256) SHA-384
DHE-RSA-AES256-SHA384 0x00, 0x9F DHE RSA AES-GCM(256) SHA384
ECDHE-RSA-CAMELLIA-CBC-128 0xC0, 0x76 ECDHE RSA Camellia-CBC(128) SHA256
ECDHE-RSA-CAMELLIA-CBC-256 0xC0, 0x77 ECDHE RSA Camellia-CBC(256) SHA384
DHE-RSA-AES128-SHA 0x00, 0x33 DHE RSA AES-CBC(128) SHA1
DHE-RSA-AES256-SHA 0x00, 0x39 DHE RSA AES-CBC(256) SHA1
DHE-RSA-CAMELLIA128-SHA 0x00, 0x45 DHE RSA Camellia-CBC(128) SHA1
DHE-RSA-CAMELLIA256-SHA 0x00, 0x88 DHE RSA Camellia-CBC(256) SHA1
ECDHE-RSA-AES128-SHA 0xC0, 0x13 ECDHE RSA AES-CBC(128) SHA1
ECDHE-RSA-AES256-SHA 0xC0, 0x14 ECDHE RSA AES-CBC(256) SHA1
DHE-RSA-AES128-SHA256 0x00, 0x67 DHE RSA AES-CBC(128) SHA256
DHE-RSA-AES256-SHA256 0x00, 0x6B DHE RSA AES-CBC(256) SHA256
DHE-RSA-CAMELLIA128-SHA256 0x00, 0xBE DHE RSA Camellia-CBC(128) SHA256
DHE-RSA-CAMELLIA256-SHA256 0x00, 0xC4 DHE RSA Camellia-CBC(256) SHA256
ECDHE-RSA-AES128-SHA256 0xC0, 0x27 ECDHE RSA AES-CBC(128) SHA256
ECDHE-RSA-AES256-SHA384 0xC0, 0x28 ECDHE RSA AES-CBC(256) SHA384

The fields above are :

{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}

97086 - Server Message Block (SMB) Protocol Version 1 Enabled
-
Synopsis
The remote Windows host supports the SMBv1 protocol.
Description
The remote Windows host supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, the Shadow Brokers group reportedly has an exploit that affects SMB; however, it is unknown if the exploit affects SMBv1 or another version. In response to this, US-CERT recommends that users disable SMBv1 per SMB best practices to mitigate these potential issues.
See Also
Solution
Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.
Risk Factor
None
Plugin Information
Published: 2017/02/09, Modified: 2020/06/12
Plugin Output

tcp/445/cifs


SMBv1 server is enabled :
- HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : NULL or missing
SMB1protocol feature is enabled based on the following key :
- HKLM\SYSTEM\CurrentControlSet\Services\srv
SMBv1 client is enabled :
- HKLM\SYSTEM\CurrentControlSet\Services\mrxsmb10\Start : 2
96982 - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)
-
Synopsis
The remote host supports the SMBv1 protocol.
Description
The remote host (Windows and/or Samba server) supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, most security and compliance agencies recommend that users disable SMBv1 per SMB best practices.
See Also
Solution
Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.
Risk Factor
None
References
XREF IAVT:0001-T-0710
Plugin Information
Published: 2017/02/03, Modified: 2025/08/13
Plugin Output

tcp/445/cifs


The remote host supports SMBv1.
160486 - Server Message Block (SMB) Protocol Version Detection
-
Synopsis
Verify the version of SMB on the remote host.
Description
The Server Message Block (SMB) Protocol provides shared access to files and printers across nodes on a network.
See Also
Solution
Disable SMB version 1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139, for all boundary devices.
Risk Factor
None
Plugin Information
Published: 2022/05/04, Modified: 2022/05/04
Plugin Output

tcp/445/cifs

- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB2 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB3 : Key not found.
- SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1 : Key not found.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/80/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5800/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5900/vnc

A vnc server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/5985/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/47001/www

A web server is running on this port.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/51528/www

A TLSv1.3 server answered on this port.

tcp/51528/www

A web server is running on this port through TLSv1.3.

22964 - Service Detection
-
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2025/12/08
Plugin Output

tcp/51529/www

A web server is running on this port.

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/80/www


URL : http://172.17.100.73/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/5985/www


URL : http://172.17.100.73:5985/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/47001/www


URL : http://172.17.100.73:47001/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/51528/www


URL : https://172.17.100.73:51528/cgi-bin/meteobridge
Version : unknown
Authenticated : False

278501 - Smartbedded Meteobridge Web Detection
-
Synopsis
The web UI for Smartbedded Meteobridge was detected on the remote host.
Description
Smartbedded Meteobridge, a dedicated weather monitoring application, is running on the remote host.

Note: Basic HTTP Authentication credentials are required to obtain the version.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/12, Modified: 2025/12/15
Plugin Output

tcp/51529/www


URL : http://172.17.100.73:51529/cgi-bin/meteobridge
Version : unknown
Authenticated : False

161455 - Supersedence Data Builder
-
Synopsis
Supersedence data.
Description
Collects and stores supersedence patch data for various patch types.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/24, Modified: 2025/07/14
Plugin Output

tcp/0

Supersedence patch data summary :
- MSKB : 169


Plugin debug log has been attached.
25220 - TCP/IP Timestamps Supported
-
Synopsis
The remote service implements TCP timestamps.
Description
The remote host implements TCP timestamps, as defined by RFC1323. A side effect of this feature is that the uptime of the remote host can sometimes be computed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/05/16, Modified: 2023/10/17
Plugin Output

tcp/0

277654 - TLS Supported Groups
-
Synopsis
The remote service negotiates TLS supported curve groups.
Description
This plugin detects which TLS supported groups entries are supported by the remote service.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/12/08, Modified: 2025/12/10
Plugin Output

tcp/51528/www


These are the TLS supported groups offered by the remote server :


TLS supported groups :

Name Code
--------------------------
x25519 0x001d
secp256r1 0x0017
x448 0x001e
secp521r1 0x0019
secp384r1 0x0018
ffdhe2048 0x0100
ffdhe3072 0x0101
ffdhe4096 0x0102
ffdhe6144 0x0103
ffdhe8192 0x0104

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/1433/mssql

TLSv1.1 is enabled and the server supports at least one cipher.

121010 - TLS Version 1.1 Protocol Detection
-
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.1.
TLS 1.1 lacks support for current and recommended cipher suites.
Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1

As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
See Also
Solution
Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
Risk Factor
None
References
XREF CWE:327
Plugin Information
Published: 2019/01/08, Modified: 2023/04/19
Plugin Output

tcp/3389/msrdp

TLSv1.1 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/1433/mssql

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/3389/msrdp

TLSv1.2 is enabled and the server supports at least one cipher.

136318 - TLS Version 1.2 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.2.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/05/04, Modified: 2020/05/04
Plugin Output

tcp/51528/www

TLSv1.2 is enabled and the server supports at least one cipher.
138330 - TLS Version 1.3 Protocol Detection
-
Synopsis
The remote service encrypts traffic using a version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.3.
See Also
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2020/07/09, Modified: 2023/12/13
Plugin Output

tcp/51528/www

TLSv1.3 is enabled and the server supports at least one cipher.

110095 - Target Credential Issues by Authentication Protocol - No Issues Found
-
Synopsis
Nessus was able to log in to the remote host using the provided credentials. No issues were reported with access, privilege, or intermittent failure.
Description
Valid credentials were provided for an authentication protocol on the remote target and Nessus did not log any subsequent errors or failures for the authentication protocol.

When possible, Nessus tracks errors or failures related to otherwise valid credentials in order to highlight issues that may result in incomplete scan results or limited scan coverage. The types of issues that are tracked include errors that indicate that the account used for scanning did not have sufficient permissions for a particular check, intermittent protocol failures which are unexpected after the protocol has been negotiated successfully earlier in the scan, and intermittent authentication failures which are unexpected after a credential set has been accepted as valid earlier in the scan. This plugin reports when none of the above issues have been logged during the course of the scan for at least one authenticated protocol. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for issues to be encountered for one protocol and not another.
For example, authentication to the SSH service on the remote target may have consistently succeeded with no privilege errors encountered, while connections to the SMB service on the remote target may have failed intermittently.

- Resolving logged issues for all available authentication protocols may improve scan coverage, but the value of resolving each issue for a particular protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol and what particular check failed. For example, consistently successful checks via SSH are more critical for Linux targets than for Windows targets, and likewise consistently successful checks via SMB are more critical for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0520
Plugin Information
Published: 2018/05/24, Modified: 2025/08/28
Plugin Output

tcp/445/cifs


Nessus was able to log into the remote host with no privilege or access
problems via the following :

User: '172.17.100.73\tidua'
Port: 445
Proto: SMB
Method: password
141118 - Target Credential Status by Authentication Protocol - Valid Credentials Provided
-
Synopsis
Valid credentials were provided for an available authentication protocol.
Description
Nessus was able to determine that valid credentials were provided for an authentication protocol available on the remote target because it was able to successfully authenticate directly to the remote target using that authentication protocol at least once. Authentication was successful because the authentication protocol service was available remotely, the service was able to be identified, the authentication protocol was able to be negotiated successfully, and a set of credentials provided in the scan policy for that authentication protocol was accepted by the remote service. See plugin output for details, including protocol, port, and account.

Please note the following :

- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed via SSH but fail via SMB, while no credentials were provided for an available SNMP service.

- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux targets.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/10/15, Modified: 2024/03/25
Plugin Output

tcp/445/cifs


Nessus was able to log in to the remote host via the following :

User: '172.17.100.73\tidua'
Port: 445
Proto: SMB
Method: password

92433 - Terminal Services History
-
Synopsis
Nessus was able to gather terminal service connection information.
Description
Nessus was able to generate a report on terminal service connections on the target system.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Terminal Services Client
- Production
- Production
- Production
- Production


Terminal Services Server
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617
- Production
- Production
- Production
- Production
- Production
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-18
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133_Classes
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133_Classes
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133_Classes
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133_Classes
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133_Classes
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965_Classes
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
- S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-1549978933-2891762758-2075524219-3728768389-1145206490_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-309224134-970686483-1999427595-3240087295-3167920316_Classes
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965
- S-1-5-80-1985561900-798682989-2213159822-1904180398-3434236965
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235
- S-1-5-21-3119273522-2427777209-1705870880-500_Classes
- S-1-5-21-3119273522-2427777209-1705870880-500_Classes
- S-1-5-21-3119273522-2427777209-1705870880-500_Classes
- S-1-5-21-3119273522-2427777209-1705870880-500_Classes
- S-1-5-21-3119273522-2427777209-1705870880-500_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235_Classes
- S-1-5-80-3477044410-376262199-2110164357-2030828471-4165405235_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes
- S-1-5-80-2575449109-2369498003-86869817-2770163484-1998650617_Classes


Extended Terminal Services report attached.

64814 - Terminal Services Use SSL/TLS
-
Synopsis
The remote Terminal Services use SSL/TLS.
Description
The remote Terminal Services is configured to use SSL/TLS.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/02/22, Modified: 2023/07/10
Plugin Output

tcp/3389/msrdp

Subject Name:

Common Name: XHwakEyeSrv

Issuer Name:

Common Name: XHwakEyeSrv

Serial Number: 1E 62 3B DA 42 5F 32 BF 49 3F E3 13 B5 71 AB 77

Version: 3

Signature Algorithm: SHA-256 With RSA Encryption

Not Valid Before: Sep 02 01:34:30 2025 GMT
Not Valid After: Mar 04 01:34:30 2026 GMT

Public Key Info:

Algorithm: RSA Encryption
Key Length: 2048 bits
Public Key: 00 AB 9A 14 0E 05 28 43 0B D5 DC E4 C2 88 B4 A3 76 A3 27 41
8E D8 DB 28 65 53 A8 92 56 D1 BF 41 47 EE 0B D2 B9 E3 E1 DF
76 A6 8A 22 A5 1A 72 BA D4 D1 30 38 23 77 62 A2 6E 69 00 A6
33 23 F2 27 51 6E 59 58 BA CC 25 9D 09 E7 9F EA 49 30 C1 9D
F6 92 CC 4C 2B F6 F9 AC 80 B1 D4 92 2A 3F 48 4D ED AF 4D 5C
0A 2B AE 21 57 1E B8 69 12 C1 79 97 35 AD 5B A0 23 14 3F 66
08 D7 4D 56 1D C2 D2 D1 BF 49 5C D1 EA 2E 96 27 32 8B F7 77
63 2A 13 EA 36 1A 36 98 2E 4B A8 7A 63 2E 47 BF 83 9C 44 7D
5F 71 AF C3 DF 03 C8 38 CE 25 E0 49 DF 9B 72 46 04 11 4B 0F
BC 35 85 B5 54 C4 14 83 F0 B0 E7 E3 21 AB 45 AB B1 99 E1 C4
1C D5 3F 07 CA 2D 4C CF F4 E6 8E DE E1 29 6C FE A3 46 56 D8
5A 8B E9 C5 B9 FF 3B 4B CA D4 1A 1F 3E DD AE 8B 80 0A A7 AA
8C F4 E7 15 98 FC A5 E3 4D 1F 50 E0 C6 61 3B 6E 43
Exponent: 01 00 01

Signature Length: 256 bytes / 2048 bits
Signature: 00 7F 95 AB F2 92 FC 45 01 F1 FE E3 92 D5 B3 E7 2F 17 98 A3
D5 CF 22 DD A2 5B 47 61 FC E5 93 DB FC C7 5F D4 25 8C CC 36
27 F3 E8 24 4F B5 ED 48 AD 18 A3 0A 70 03 E7 E3 59 09 74 C0
29 0B 41 60 B3 6A 1C 4D 64 42 40 AF 4D D9 9B B9 3B D0 D3 F6
8F 62 D5 73 41 59 6F 9F 6E D6 33 48 FB F9 7C E6 22 42 6E 18
F2 01 77 BA B9 D6 06 2D 03 46 F4 0A C8 B1 A1 80 79 60 F6 DE
6E 95 53 AA AA E2 4F 83 9D 0B 44 D1 0D ED 7A AC AC 64 36 29
9F 41 08 2D FD 71 6F F7 42 23 D7 B4 51 51 7F 17 2E 5D EB 7D
D7 C3 BE 2A 4A C2 9F 67 53 98 6A 32 CB 6A F0 78 5F 0E DB A4
82 13 6D 4F FC 90 45 A8 8A 6F B9 FD E8 A5 34 2D B6 C8 0E DD
D9 A2 97 40 B9 32 B2 C0 38 D5 1B 4A 5F 08 82 D3 34 D6 BA 73
3B F6 A4 0D 4C A8 EA 72 93 50 E8 13 41 CD D1 F0 D7 1F 74 CA
91 9F E3 73 16 5B 0A 53 57 AC 89 7C D8 08 D5 DB 1B

Extension: Extended Key Usage(2.5.29.37)
Critical: 0
Purpose#1: Web Server Authentication (1.3.6.1.5.5.7.3.1)


Extension: Key Usage(2.5.29.15)
Critical: 0
Key Usage: Key Encipherment, Data Encipherment

56468 - Time of Last System Startup
-
Synopsis
The system has been started.
Description
Using the supplied credentials, Nessus was able to determine when the host was last started.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/10/12, Modified: 2018/06/19
Plugin Output

tcp/0


20260105070037.493454+330

10287 - Traceroute Information
-
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output

udp/0

For your information, here is the traceroute from 172.17.100.38 to 172.17.100.73 :
172.17.100.38
172.17.100.73

Hop Count: 1

11154 - Unknown Service Detection: Banner Retrieval
-
Synopsis
There is an unknown service running on the remote host.
Description
Nessus was unable to identify a service on the remote host even though it returned a banner of some type.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/11/18, Modified: 2022/07/26
Plugin Output

tcp/25002


If you know what this service is and think the banner could be used to
identify it, please send a description of the service along with the
following output to svc-signatures@nessus.org :

Port : 25002
Type : help
Banner :
0x00: 36 00 4B 00 78 9C F3 66 A8 67 F4 F3 74 0B 89 34 6.K.x..f.g..t..4
0x10: 35 50 40 01 8C 0C 5D 06 EA 0C 3C 53 D5 19 FE 48 5P@...]...<S...H
0x20: A8 33 BC C8 55 67 50 AD 51 67 D8 FA FF FF 7F 0E .3..UgP.Qg......
0x30: 3B 0D 06 6C 00 00 57 CA 0D C4 32 00 4B 00 78 9C ;..l..W...2.K.x.
0x40: F3 66 A8 67 0C 76 F5 0B 76 8D 50 40 05 A9 0C 3F .f.g.v..v.P@...?
0x50: DA EA 19 F4 4E 37 30 B0 38 D7 33 28 9A 36 30 18 ....N70.8.3(.60.
0x60: 14 37 30 EC F8 FF FF 3F 03 0E 00 00 95 4D 0E D1 .70....?.....M..
0x70: 38 00 4B 00 78 9C F3 66 A8 67 F4 F3 74 0B 89 74 8.K.x..f.g..t..t
0x80: 72 F4 F3 56 40 02 9C 0C CA 99 51 0C 67 D5 A3 19 r..V@.....Q.g...
0x90: 64 9C A3 18 9E 3F 88 62 E0 12 8E 66 D8 FE FF FF d....?.b...f....
0xA0: FF 70 8B 18 06 6C 00 00 91 AE 0F 21 .p...l.....!


Nessus detected the following process listening on this port :

javaw.exe

92434 - User Download Folder Files
-
Synopsis
Nessus was able to enumerate downloaded files on the remote host.
Description
Nessus was able to generate a report of all files listed in the default user download folder.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

C:\\Users\Administrator\Downloads\allo.csv
C:\\Users\Administrator\Downloads\ALLOCATIONDIFF_408_02122025.txt
C:\\Users\Administrator\Downloads\apache-tomcat-9.0.104-windows-x64.zip
C:\\Users\Administrator\Downloads\apache-tomcat-9.0.89.exe
C:\\Users\Administrator\Downloads\BASEPOSITION_408_12122025.csv
C:\\Users\Administrator\Downloads\BSERISK\BSERISK_Delta_20251219-03.csv
C:\\Users\Administrator\Downloads\BSERISK_Delta_20251219-03.csv
C:\\Users\Administrator\Downloads\C410.pdf
C:\\Users\Administrator\Downloads\cash.xls
C:\\Users\Administrator\Downloads\CDX_INTRADAY_SHRTCOLL_0408_04042025_04.CSV
C:\\Users\Administrator\Downloads\CDX_INTRADAY_SHRTCOLL_0408_25092025_01.CSV
C:\\Users\Administrator\Downloads\CDX_SHRTCOLL_0408_24092025 (1).CSV
C:\\Users\Administrator\Downloads\CDX_SHRTCOLL_0408_24092025.CSV
C:\\Users\Administrator\Downloads\ClientAllocation_408_20251220120259.csv
C:\\Users\Administrator\Downloads\ClientAllocation_408_20251220120453.csv
C:\\Users\Administrator\Downloads\CLIENTBENMAPPING_25092025.txt
C:\\Users\Administrator\Downloads\ClientMarginUtilEQ_25092025_1217pm.csv
C:\\Users\Administrator\Downloads\ClientMarginUtilFo_25092025_1217pm.csv
C:\\Users\Administrator\Downloads\CM_TRADE_DATA15122025.txt
C:\\Users\Administrator\Downloads\Contract_Delta_04122025.csv
C:\\Users\Administrator\Downloads\Contract_Delta_05122025.csv
C:\\Users\Administrator\Downloads\cp039412 (1).exe
C:\\Users\Administrator\Downloads\cp039412.exe
C:\\Users\Administrator\Downloads\cp049814.compsig
C:\\Users\Administrator\Downloads\cp049814.exe
C:\\Users\Administrator\Downloads\cp059763.compsig
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240709080448_Capital.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240709080532_FNO.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240709080544_CDS.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240710082120.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240710082125.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240710082129.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240711080725.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240711080729.csv
C:\\Users\Administrator\Downloads\CSV\ClientAllocation_408_20240711080733.csv
C:\\Users\Administrator\Downloads\Currency_ClientAllocation_408_20240625080838.csv
C:\\Users\Administrator\Downloads\desktop.ini
C:\\Users\Administrator\Downloads\EDX_INTRADAY_SHRTCOLL_0408_04042025_04.CSV
C:\\Users\Administrator\Downloads\EDX_INTRADAY_SHRTCOLL_0408_25092025_01.CSV
C:\\Users\Administrator\Downloads\EDX_SHRTCOLL_0408_12122025.CSV
C:\\Users\Administrator\Downloads\EDX_SHRTCOLL_0408_24092025.CSV
C:\\Users\Administrator\Downloads\EQ_INTRADAY_SHRTCOLL_0408_04042025_04.CSV
C:\\Users\Administrator\Downloads\EQ_INTRADAY_SHRTCOLL_0408_25092025_01.CSV
C:\\Users\Administrator\Downloads\EQ_MGDTLS_MGTM_0408_12122025_05.CSV
C:\\Users\Administrator\Downloads\EQ_SHRTCOLL_0408_12122025.CSV
C:\\Users\Administrator\Downloads\EQ_SHRTCOLL_0408_24092025.CSV
C:\\Users\Administrator\Downloads\fo_secban_19122025.csv
C:\\Users\Administrator\Downloads\f_mwplbasepos02_09018_20251205 (1).csv
C:\\Users\Administrator\Downloads\F_TM_DELOI_408_05122025.csv
C:\\Users\Administrator\Downloads\ICCLOI_05122025 (1).csv
C:\\Users\Administrator\Downloads\ICCLOI_05122025.csv
C:\\Users\Administrator\Downloads\jdk-25_windows-x64_bin.exe
C:\\Users\Administrator\Downloads\jdk-8u401-windows-x64.exe
C:\\Users\Administrator\Downloads\Margin Detail Report 20250331.csv
C:\\Users\Administrator\Downloads\Margin_ICCL_CM_0_TM_408_20250404_P_1530.CSV
C:\\Users\Administrator\Downloads\Margin_ICCL_CM_0_TM_408_20250925_P_1100.CSV
C:\\Users\Administrator\Downloads\Margin_ICCL_FO_0_TM_408_20250404_P_1530.CSV
C:\\Users\Administrator\Downloads\Margin_ICCL_FO_0_TM_408_20250925_P_1100.CSV
C:\\Users\Administrator\Downloads\Margin_ICCL_FO_0_TM_408_20251212_F_0000.CSV
C:\\Users\Administrator\Downloads\Margin_MCXCCL_CO_0_CM_56630_20241014_F_0000.csv
C:\\Users\Administrator\Downloads\Margin_MCXCCL_CO_0_CM_56630_20250114_F_0000.csv
C:\\Users\Administrator\Downloads\Margin_MCXCCL_CO_0_CM_56630_20251212_F_0000.csv
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_01022025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_03022025_S.E003
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_03032025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_04022025.E004
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_06012025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_06112024.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_09122024_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_09122024_S.E002
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_13012025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_13122024_S.E002
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_14012025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_14022025_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_14112024_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_15102024_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_16082024.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_18112024_S.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_19122024.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_19122024.E002
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_20022025.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_27012025.E001
C:\\Users\Administrator\Downloads\MCCLCOLL_56630_30122024.E001
C:\\Users\Administrator\Downloads\MCXRPF-20250318-0445-01-I.spn
C:\\Users\Administrator\Downloads\MCXRPF-20250318-0930-02-I.spn
C:\\Users\Administrator\Downloads\MCXRPF-20250328-2345-10-E.spn
C:\\Users\Administrator\Downloads\MCXRPF-20250331-0041-01-I (1).spn
C:\\Users\Administrator\Downloads\MCXRPF-20250331-0041-01-I.spn
C:\\Users\Administrator\Downloads\MCXRPF-20250424-1300-04-I.spn
C:\\Users\Administrator\Downloads\MCXRPF-20251212-0537-01-I.spn
C:\\Users\Administrator\Downloads\MCXRPF-20251212-2359-10-E.spn
C:\\Users\Administrator\Downloads\MCXRPF-20251218-2359-10-E.spn
C:\\Users\Administrator\Downloads\MCX_MARGIN_56630_20241118.csv
C:\\Users\Administrator\Downloads\MCX_MARGIN_56630_20250512.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_01.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_03.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_04.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_05.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_06.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_07.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20241118_08.csv
C:\\Users\Administrator\Downloads\MCX_PeakMargin56630_20250424_03.csv
C:\\Users\Administrator\Downloads\MCX_ProductMaster.csv
C:\\Users\Administrator\Downloads\MCX_Sensitivity&DevolvmentMargin_56630_20241118.csv
C:\\Users\Administrator\Downloads\MCX_Sensitivity&DevolvmentMargin_56630_20250219.csv
C:\\Users\Administrator\Downloads\MTF MARGIN SHORTFALL 14.07.2025.csv
C:\\Users\Administrator\Downloads\MTF MARGIN SHORTFALL 22.07.2025.csv
C:\\Users\Administrator\Downloads\ndp472-kb4054531-web.exe
C:\\Users\Administrator\Downloads\NDP481-Web (1).exe
C:\\Users\Administrator\Downloads\NDP481-Web (2).exe
C:\\Users\Administrator\Downloads\NDP481-Web.exe
C:\\Users\Administrator\Downloads\npp.8.6.6.Installer.x64.exe
C:\\Users\Administrator\Downloads\nsccl.20241121.i01.spn
C:\\Users\Administrator\Downloads\nsccl.20241121.i1.zip
C:\\Users\Administrator\Downloads\nsccl.20241122.i05 (1).spn.gz
C:\\Users\Administrator\Downloads\nsccl.20241122.i05 (2).spn
C:\\Users\Administrator\Downloads\nsccl.20241122.i05 (2).spn.gz
C:\\Users\Administrator\Downloads\nsccl.20241122.i05.spn.gz
C:\\Users\Administrator\Downloads\nsccl.20241125.i05.spn
C:\\Users\Administrator\Downloads\nsccl.20241125.i05.spn.gz
C:\\Users\Administrator\Downloads\nsccl.20241127.i04.spn
C:\\Users\Administrator\Downloads\nsccl.20241127.i04.spn.gz
C:\\Users\Administrator\Downloads\nsccl.20241227.s.spn
C:\\Users\Administrator\Downloads\nsccl.20241227.s.zip
C:\\Users\Administrator\Downloads\nsccl.20251205.i4.zip
C:\\Users\Administrator\Downloads\nsccl.20251205.i5.zip
C:\\Users\Administrator\Downloads\NSE_FO_ClientAllocation_408_20240625080833.csv
C:\\Users\Administrator\Downloads\Position_ICCL_FO_0_TM_408_20251212_F_0000.CSV
C:\\Users\Administrator\Downloads\Postman-win64-Setup.exe
C:\\Users\Administrator\Downloads\rename (1).zip
C:\\Users\Administrator\Downloads\rename.zip
C:\\Users\Administrator\Downloads\RES_API_0408_202503100408010001.csv
C:\\Users\Administrator\Downloads\RES_API_0408_202503100408010002.csv
C:\\Users\Administrator\Downloads\RES_API_0408_202503100408010003.csv
C:\\Users\Administrator\Downloads\RES_API_0408_202504290408010001 (1).csv
C:\\Users\Administrator\Downloads\RES_API_0408_202504290408010001.csv
C:\\Users\Administrator\Downloads\RES_API_0408_202504290408010002.csv
C:\\Users\Administrator\Downloads\RES_ICCLCOLL_0408_04042025_0004.CSV
C:\\Users\Administrator\Downloads\RES_ICCLCOLL_0408_04042025_0005.CSV
C:\\Users\Administrator\Downloads\RES_ICCLCOLL_0408_24122024_0001.CSV
C:\\Users\Administrator\Downloads\SEARCHRESULTS - 2025-11-26T090331.098.csv
C:\\Users\Administrator\Downloads\SearchResults - 2025-11-26T090331.098.xlsx
C:\\Users\Administrator\Downloads\SSMS-Setup-ENU.exe
C:\\Users\Administrator\Downloads\test.csv
C:\\Users\Administrator\Downloads\VAR121225.xls
C:\\Users\Administrator\Downloads\VAR121225.zip
C:\\Users\Administrator\Downloads\VAR151225.xls
C:\\Users\Administrator\Downloads\xHawkEyeClient\GridSettings.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\PointerStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\UTIL.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xCommonStruct.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xHawkEyeClient.exe
C:\\Users\Administrator\Downloads\xHawkEyeClient\xHawkeyeClientUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xHawkEyeStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xMail.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xNotifier.dll
C:\\Users\Administrator\Downloads\xHawkEyeClient\xtb.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\AutoDownloadNew.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer\BroadcastReceiver.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer\dalRC.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\DCTrades.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer\DC_BAL.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\GridSettings.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\MasterUpdates.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\UTIL.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xCIMAllocationServiceAPI.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xCommonStruct.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkeyeClientUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkEyeDataLayer.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkEyeServer.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkeyeServerUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkeyeService.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer\xHawkEyeStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xSPAN.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xtb.dll
C:\\Users\Administrator\Downloads\xHawkEyeServer\xTrades.exe
C:\\Users\Administrator\Downloads\xHawkEyeServer Client Ver 2.2.0.35 20240713.zip
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\GridSettings.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\PointerStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\UTIL.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xCommonStruct.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xHawkEyeClient.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xHawkeyeClientUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xHawkEyeStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xMail.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xNotifier.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeClient\xtb.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\AutoDownloadNew.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\BroadcastReceiver.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\dalRC.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\DCTrades.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\DC_BAL.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\GridSettings.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\MasterUpdates.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\UTIL.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xCIMAllocationServiceAPI.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xCommonStruct.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkeyeClientUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkEyeDataLayer.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkEyeServer.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkeyeServerUtil.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkeyeService.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xHawkEyeStructures.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xSPAN.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xtb.dll
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217\xHawkEyeServer\xTrades.exe
C:\\Users\Administrator\Downloads\xHawkEyeServerClient Ver 2.0.0.5020241217.zip
C:\\Users\Administrator\Downloads\xHawkEyeServerClient ver 2.5.0.720250207.zip
C:\\Users\Administrator\Downloads\xLimitStation_19 Jun 2024 _1_0_8.bak
C:\\Users\LKPAdmin\Downloads\desktop.ini
C:\\Users\LKPAdmin\Downloads\putty.exe
C:\\Users\Public\Downloads\desktop.ini

Download folder content report attached.
92431 - User Shell Folders Settings
-
Synopsis
Nessus was able to find the folder paths for user folders on the remote host.
Description
Nessus was able to gather a list of settings from the target system that store common user folder locations. A few of the more common locations are listed below :

- Administrative Tools
- AppData
- Cache
- CD Burning
- Cookies
- Desktop
- Favorites
- Fonts
- History
- Local AppData
- My Music
- My Pictures
- My Video
- NetHood
- Personal
- PrintHood
- Programs
- Recent
- SendTo
- Start Menu
- Startup
- Templates
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/16
Plugin Output

tcp/0

Production
- {7d1d3a04-debb-4115-95cf-2f29da2920da} : C:\Users\Administrator\Searches
- {1b3ea5dc-b587-4786-b4ef-bd1dc332aeae} : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Libraries
- {374de290-123f-4565-9164-39c4925e467b} : C:\Users\Administrator\Downloads
- recent : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent
- my video : C:\Users\Administrator\Videos
- my music : C:\Users\Administrator\Music
- {56784854-c6cb-462b-8169-88e350acb882} : C:\Users\Administrator\Contacts
- {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968} : C:\Users\Administrator\Links
- {a520a1a4-1780-4ff6-bd18-167343c5af16} : C:\Users\Administrator\AppData\LocalLow
- sendto : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo
- start menu : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu
- cookies : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies
- personal : C:\Users\Administrator\Documents
- administrative tools : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- startup : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- history : C:\Users\Administrator\AppData\Local\Microsoft\Windows\History
- nethood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts
- {4c5c32ff-bb9d-43b0-b5b4-2d72e54eaaa4} : C:\Users\Administrator\Saved Games
- {00bcfc5a-ed94-4e48-96a1-3f6217f21990} : C:\Users\Administrator\AppData\Local\Microsoft\Windows\RoamingTiles
- !do not use this registry key : Use the SHGetFolderPath or SHGetKnownFolderPath function instead
- local appdata : C:\Users\Administrator\AppData\Local
- my pictures : C:\Users\Administrator\Pictures
- templates : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates
- printhood : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
- cache : C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache
- desktop : C:\Users\Administrator\Desktop
- programs : C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- fonts : C:\Windows\Fonts
- cd burning : C:\Users\Administrator\AppData\Local\Microsoft\Windows\Burn\Burn
- favorites : C:\Users\Administrator\Favorites
- appdata : C:\Users\Administrator\AppData\Roaming
92435 - UserAssist Execution History
-
Synopsis
Nessus was able to enumerate program execution history on the remote host.
Description
Nessus was able to gather evidence from the UserAssist registry key that has a list of programs that have been executed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/11/12
Plugin Output

tcp/0

d:\xtpl\apps\uat\xhawkeye server 2.2.0.49 mcx\xhawkeyeserver.exe
d:\xtpl\apps\uat\xhawkeye server 2.5.0.6-spread\config\configeditor\configeditor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\windowspowershell\v1.0\powershell.exe
c:\users\administrator\desktop\xtpl\006.allocationserver_newversion.jar - shortcut.lnk
d:\xtpl\apps\uat\xhawkeye server 2.5.0.6-spread\xhawkeyeserver.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\system tools\task manager.lnk
c:\users\administrator\desktop\xtpl\xhawkeyeclient-2.2.0.32.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.32 new\xhawkeyeclient.exe
c:\users\administrator\desktop\xtpl\001.xhawkeyeserver - 2.2.0.39.lnk
c:\users\administrator\desktop\xtpl\xhawkeyeserver-2.2.0.32.lnk
microsoft.internetexplorer.default
{f38bf404-1d43-42f2-9305-67de0b28fc23}\system32\notepad.exe
d:\xtpl\pledge tomcat\apache-tomcat-9.0.104\bin\startup.bat
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\002.xhawkeyeserver_1.0.0.207 mcx and cds.lnk
d:\lkpsoft\mcx\mts_encrypted_v14.0.2.92\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dcomcnfg.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.39\config\configeditor\configeditor.exe
d:\xtpl\apps\xhawkeye server 2.2.0.53\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\005. xhawkeyeclient 2.2.0.39.lnk
d:\xtpl\apps\xhawkeye server_1.0.0.207\xhawkeyeserver_1.0.0.207.lnk
c:\users\administrator\desktop\sql server management studio 20.lnk
d:\xtpl\apps\xhawkeye server 2.2.0.53\config\configeditor\configeditor.exe
c:\users\administrator\desktop\xtpl\004 jbcastlite_bse(15092025).jar - shortcut.lnk
com.squirrel.postman.postman
d:\xtpl\apps\uat\xhawkeye client 2.2.0.38\xhawkeyeclient.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\accessories\notepad.lnk
c:\users\administrator\desktop\xtpl\allocationserver_newversion.jar - shortcut.lnk
d:\xtpl\new exe\xhawkeye server 25.0.10.25\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver - 2.2.0.29.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft office\microsoft excel 2010.lnk
c:\users\administrator\downloads\jdk-25_windows-x64_bin.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.53\xhawkeyeserver.exe
d:\xtpl\apps\xhawkeye server_1.0.0.207\config\configeditor\configeditor.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\paint.lnk
d:\xtpl\pledge tomcat\apache-tomcat-9.0.104\bin\tomcat9.exe
ueme_ctlsession
d:\xtpl\apps\uat\xhawkeye server 2.2.0.50 - copy\config\configeditor.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\command prompt.lnk
c:\users\administrator\desktop\xtpl\007.tomcat9.exe - shortcut.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.38\config\configeditor\configeditor.exe
d:\xtpl\config_2024\configeditor\configeditor.exe
d:\xtpl\apps\xhawkeye server 2.2.0.38\config\configeditor.exe
d:\xtpl\apps\xhawkeye client_old\xhawkeyeclient.exe
c:\users\administrator\desktop\xtpl\uat\001. xhawkeyeserver - 2.2.0.39.lnk
d:\xtpl\apps\uat\xhawkeye client 2.2.0.50\xhawkeyeclient.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\cmd.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\calc.exe
d:\lkpsoft\mcs_14.0.2.73_negative\mcs_14.0.2.73_negative_17sept\setup.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\notepad.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.50 - copy\xhawkeyeserver.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\windows powershell\windows powershell.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\servermanager.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\narrator.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.49 mcx\config\configeditor\configeditor.exe
c:\users\administrator\desktop\xhawkeyeserver.exe - shortcut.lnk
c:\users\administrator\appdata\local\temp\2\jds473141375.tmp\jre-8u431-windows-au.exe
microsoft.autogenerated.{4a53e500-33be-add9-4671-88c6ca5b7c89}
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe - 25.0.10.05 - span delta.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\dxdiag.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\notepad.lnk
d:\xtpl\tomcat\bin\startup.bat
d:\xtpl\config_2024\configeditor.exe
d:\xtpl\tomcat\bin\tomcat9.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 20\common7\ide\ssms.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.39\xhawkeyeserver.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\gpupdate.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\snipping tool.lnk
c:\users\administrator\desktop\xtpl\jbcastlite(10052024).jar - shortcut.lnk
d:\xtpl\apps\uat\xhawkeye server 2.2.0.50\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\allocationserverclient.jar - shortcut.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\microsoft.net\framework\v2.0.50727\dw20.exe
c:\users\administrator\desktop\xtpl\3_bcastlite_long(16092024).jar - shortcut.lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft sql server management studio 20\common7\profiler.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver_1.0.0.207.lnk
microsoft.autogenerated.{3feac699-f0d0-bc8e-200b-290db2fde6f2}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\snippingtool.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.39\xhawkeyeclient.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\google chrome.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.32 new\config\configeditor\configeditor.exe
d:\xtpl\apps\xhawkeye client 2.2.0.32 new\config\configeditor.exe
d:\xtpl\apps\xhawkeye server_1.0.0.207\xhawkeyeserver.exe
d:\xtpl\apps\xhawkeye server 2.2.0.32 new\config\configeditor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msiexec.exe
c:\users\administrator\desktop\xtpl\not to use xhawkeyeclient.exe 2.2.0.38.lnk
c:\users\administrator\desktop\xtpl\xhawkeyeclient.exe - 2.2.0.50_new.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.50 - copy\xhawkeyeclient.exe
c:\users\administrator\desktop\xtpl\004.bcastlite_long(24042025).jar - shortcut.lnk
d:\iml-bse-cm\app\wiml.exe
c:\users\administrator\desktop\xtpl\1_allocationserver_newversion.jar - shortcut.lnk
c:\users\administrator\desktop\xtpl\uat\002. xhawkeyeclient 2.2.0.39.lnk
d:\xtpl\apps\uat\xhawkeye server 2.2.0.39\config\configeditor.exe
d:\xtpl\apps\xhawkeye server 2.2.0.38\xhawkeyeserver.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.38\config\configeditor\configeditor.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\microsoft excel 2010.lnk
d:\lkpsoft\cp015778.exe
\\192.168.150.175\d$\lkpsoft\office2010\setup.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\microsoft sql server tools 20\sql server management studio 20.lnk
c:\users\administrator\desktop\xtpl\002.xhawkeyeserver_1.0.0.207 mcx and cds.lnk
d:\xtpl\apps\uat\xhawkeye server 06102025\xhawkeye server 06102025\xhawkeye server 25.0.8.20 - copy\config\configeditor\configeditor.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rundll32.exe
{f38bf404-1d43-42f2-9305-67de0b28fc23}\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe
{6d809377-6af0-444b-8957-a3773f02200e}\notepad++\notepad++.exe
microsoft.windows.remotedesktop
c:\progra~2\mif5ba~1\office14\ois.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\easeofaccessdialog.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe 2.2.0.35.lnk
c:\users\administrator\appdata\local\temp\2\jds388734625.tmp\jre-8u451-windows-au.exe
kasperskylab.kis.ui.toasts
c:\users\administrator\appdata\local\temp\2\jds1080542171.tmp\jre-8u471-windows-au.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mspaint.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver_1.0.0.207 mcx and cds.lnk
d:\xtpl\apps\uat\xhawkeye server 2.2.0.39 - copy\xhawkeyeserver.exe
{6d809377-6af0-444b-8957-a3773f02200e}\java\jre-1.8\bin\javaw.exe
d:\xtpl\apps\xhawkeye client 2.2.0.38\config\configeditor.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.49 mcx\config\configeditor.exe
c:\users\administrator\desktop\xtpl\3_wiml - shortcut.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.32\xhawkeyeclient.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.39 - copy\xhawkeyeclient.exe
{a77f5d77-2e2b-44c3-a6a2-aba601054a51}\system tools\control panel.lnk
c:\users\administrator\desktop\xtpl\002. xhawkeyeclient 2.2.0.39.lnk
microsoft.autogenerated.{8abd94fb-e7d6-84a6-a997-c918edde0ae5}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\openwith.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.38\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\xhawkeyeclient -2.2.0.29 (2).lnk
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft office\office14\clview.exe
d:\xtpl\apps\xhawkeye server 2.2.0.32 new\config\configeditor\configeditor.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.39\config\configeditor.exe
{d65231b0-b2f1-4857-a4ce-a8e7c6ea7d27}\notepad.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\administrative tools\event viewer.lnk
{f38bf404-1d43-42f2-9305-67de0b28fc23}\regedit.exe
d:\xtpl\apps\xhawkeye client 2.2.0.53\config\configeditor.exe
c:\users\administrator\desktop\xtpl\extranetapi_07012026.jar - shortcut.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.38\xhawkeyeclient.exe
d:\xtpl\apps\xhawkeye client 2.2.0.53\xhawkeyeclient.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver_old-2.2.0.32.lnk
c:\users\administrator\appdata\local\temp\2\jds475448390.tmp\jre-8u461-windows-au.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.53\xhawkeyeclient.exe
d:\xtpl\apps\uat\xhawkeye server 2.2.0.39\config\configeditor\configeditor.exe
c:\users\administrator\desktop\xtpl\2_wiml - shortcut.lnk
c:\users\administrator\desktop\xtpl\pledge tomcat .bat - shortcut.lnk
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\internet explorer.lnk
c:\users\administrator\desktop\xtpl\xhawkeyeclient_old-2.2.0.32.lnk
d:\xtpl\apps\xhawkeye server 2.2.0.38\config\configeditor\configeditor - copy.exe
{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\taskbar\file explorer.lnk
c:\users\administrator\desktop\xtpl\006.allocationserver.jar - shortcut.lnk
d:\xtpl\apps\uat\xhawkeye server 06102025\xhawkeye server 06102025\xhawkeye server 25.0.8.20 - copy\xhawkeyeserver.exe
d:\xtpl\apps\xhawkeye server 2.2.0.38\config\configeditor - copy\configeditor.exe
d:\xtpl\apps\xhawkeye server 2.2.0.32 allocation\xhawkeyeserver.exe
d:\xtpl\apps\uat\xhawkeye client 2.2.0.39 - copy\config\configeditor\configeditor.exe
d:\xtpl\apps\xhawkeye server 2.2.0.29\xhawkeyeserver - 2.2.0.29.lnk
d:\xtpl\apps\xhawkeye client 2.2.0.53\config\configeditor\configeditor.exe
c:\users\administrator\desktop\xtpl\001. xhawkeyeserver - 2.2.0.39.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\winrar\winrar.exe
c:\users\administrator\appdata\local\temp\2\{843c2fa6-f983-4aee-99b3-f75dcd436cc7}\cpqsetup.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft office\office14\ois.exe
{6d809377-6af0-444b-8957-a3773f02200e}\windows nt\accessories\wordpad.exe
d:\xtpl\apps\xhawkeye server 2.2.0.38\config\configeditor\configeditor.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe - 2.2.0.53_for mcx m2m.lnk
microsoft.autogenerated.{bd3f924e-55fb-a1ba-9de6-b50f9f2460ac}
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\services.msc
microsoft.autogenerated.{bb044bfd-25b7-2faa-22a8-6371a93e0456}
microsoft.windows.explorer
microsoft.autogenerated.{923dd477-5846-686b-a659-0fccd73851a8}
microsoft.windows.windowsinstaller
c:\users\administrator\desktop\xtpl\xhawkeyeclient.exe 2.2.0.38.lnk
c:\users\administrator\desktop\xtpl\tomcat9.exe - shortcut.lnk
c:\users\administrator\desktop\xtpl\wiml - shortcut.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\win32calc.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\rdpclip.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\google chrome.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\calculator.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\systempropertiesadvanced.exe
{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\microsoft office\office14\excel.exe
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\accessories\remote desktop connection.lnk
microsoft.windows.shell.rundialog
c:\progra~2\mif5ba~1\office14\excel.exe
c:\users\administrator\desktop\postman.lnk
c:\users\administrator\desktop\xtpl\jbcastlite_long(16092024).jar - shortcut.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\mmc.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\runtimebroker.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\control.exe
microsoft.windows.controlpanel
c:\users\administrator\desktop\wiml - shortcut.lnk
{0139d44e-6afe-49f2-8690-3dafcae6ffb8}\hp system tools\hp array configuration utility (64-bit)\setup hp array configuration utility.lnk
c:\users\administrator\appdata\local\temp\~nsu1.tmp\un.exe
c:\users\administrator\desktop\xtpl\4_tomcat9.exe - shortcut.lnk
c:\users\administrator\appdata\local\temp\2\jds1079656765.tmp\jre-8u441-windows-au.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe - 2.2.0.50_new.lnk
d:\xtpl\apps\xhawkeye server 2.2.0.32\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\xhawkeyeclient.exe -2.2.0.53.lnk
d:\xtpl\apps\uat\xhawkeye client 2.2.0.38\config\configeditor\configeditor.exe
{6d809377-6af0-444b-8957-a3773f02200e}\java\jdk-22\bin\javaw.exe
{6d809377-6af0-444b-8957-a3773f02200e}\java\jdk-25\bin\javaw.exe
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe 2.2.0.38.lnk
c:\users\public\desktop\google chrome.lnk
d:\xtpl\apps\xhawkeye server 2.2.0.32 new\xhawkeyeserver.exe
c:\users\administrator\desktop\xtpl\xhawkeyeclient.exe 2.2.0.35.lnk
d:\lkpsoft\sanernow_lkp_window_cm_windows_x86_6.3\sanernow_windows_x86_6.3.exe
chrome
c:\users\administrator\desktop\xtpl\xhawkeyeserver.exe - 2.2.0.53.lnk
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\winver.exe
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\credentialuibroker.exe
ueme_ctlcuacount:ctor
{1ac14e77-02e7-4e5d-b744-2eb1ae5198b7}\msdt.exe
c:\users\administrator\desktop\xtpl\2_bcastlite_long(16092024).jar - shortcut.lnk
c:\users\administrator\desktop\xtpl\004.bcastlite_long(16092024).jar - shortcut.lnk
windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
c:\users\administrator\desktop\xtpl\00003.spread expiry xhawkeyeserver.exe.lnk
c:\users\administrator\desktop\xtpl\allocationserver.jar - shortcut.lnk
c:\users\administrator\desktop\xtpl\003.wiml - shortcut.lnk
{6d809377-6af0-444b-8957-a3773f02200e}\compaq\cpqacuxe\bin\hpacubin.exe

Extended userassist report attached.

10758 - VNC HTTP Server Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2001/09/14, Modified: 2020/06/12
Plugin Output

tcp/5800/www

19288 - VNC Server Security Type Detection
-
Synopsis
A VNC server is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/07/22, Modified: 2021/07/13
Plugin Output

tcp/5900/vnc


The remote VNC server supports the following security types :\n\n 5 (RA2)
129
10342 - VNC Software Detection
-
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.
See Also
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2000/03/07, Modified: 2017/06/12
Plugin Output

tcp/5900/vnc


The highest RFB protocol version supported by the server is :

4.1

24269 - WMI Available
-
Synopsis
WMI queries can be made against the remote host.
Description
The supplied credentials can be used to make WMI (Windows Management Instrumentation) requests against the remote host over DCOM.

These requests can be used to gather information about the remote host, such as its current state, network interface configuration, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/02/03, Modified: 2025/12/15
Plugin Output

tcp/445/cifs

The remote host returned the following caption from Win32_OperatingSystem:

Microsoft Windows Server 2016 Datacenter

52001 - WMI QuickFixEngineering (QFE) Enumeration
-
Synopsis
The remote Windows host has quick-fix engineering updates installed.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates quick-fix engineering updates installed on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/16, Modified: 2025/12/15
Plugin Output

tcp/0


Here is a list of quick-fix engineering updates installed on the
remote system :

+ KB4049065
- Description : Update
- InstalledOn : 2/2/2018
- SystemName : XHWAKEYESRV
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=4049065

+ KB4054590
- Description : Update
- InstalledOn : 6/6/2024
- SystemName : XHWAKEYESRV
- InstalledBy : XHWAKEYESRV\Production
- Caption : http://support.microsoft.com/?kbid=4054590

+ KB5037016
- Description : Security Update
- InstalledOn : 5/31/2024
- SystemName : XHWAKEYESRV
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : https://support.microsoft.com/help/5037016

+ KB4103720
- Description : Update
- InstalledOn : 5/31/2024
- SystemName : XHWAKEYESRV
- InstalledBy : NT AUTHORITY\SYSTEM
- Caption : http://support.microsoft.com/?kbid=4103720
44871 - WMI Windows Feature Enumeration
-
Synopsis
It is possible to enumerate Windows features using WMI.
Description
Nessus was able to enumerate the server features of the remote host by querying the 'Win32_ServerFeature' class of the '\Root\cimv2' WMI namespace for Windows Server versions or the 'Win32_OptionalFeature' class of the '\Root\cimv2' WMI namespace for Windows Desktop versions.

Note that Features can only be enumerated for Windows 7 and later for desktop versions.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0754
Plugin Information
Published: 2010/02/24, Modified: 2025/12/15
Plugin Output

tcp/0


Nessus enumerated the following Windows features :

- .NET Environment 3.5
- .NET Extensibility 3.5
- .NET Framework 3.5 (includes .NET 2.0 and 3.0)
- .NET Framework 3.5 Features
- .NET Framework 4.6
- .NET Framework 4.6 Features
- ASP.NET 4.6
- Application Development
- Configuration APIs
- File Server
- File and Storage Services
- File and iSCSI Services
- HTTP Activation
- IIS Management Console
- Management Tools
- Non-HTTP Activation
- Process Model
- Request Filtering
- SMB 1.0/CIFS File Sharing Support
- Security
- Storage Services
- TCP Port Sharing
- Telnet Client
- WCF Services
- Web Server
- Web Server (IIS)
- Windows PowerShell
- Windows PowerShell 2.0 Engine
- Windows PowerShell 5.1
- Windows PowerShell ISE
- Windows Process Activation Service
- WoW64 Support

33139 - WS-Management Server Detection
-
Synopsis
The remote web server is used for remote management.
Description
The remote web server supports the Web Services for Management (WS-Management) specification, a general web services protocol based on SOAP for managing systems, applications, and other such entities.
See Also
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2008/06/11, Modified: 2021/05/19
Plugin Output

tcp/5985/www


Here is some information about the WS-Management Server :

Product Vendor : Microsoft Corporation
Product Version : OS: 0.0.0 SP: 0.0 Stack: 3.0

20108 - Web Server / Application favicon.ico Vendor Fingerprinting
-
Synopsis
The remote web server contains a graphic image that is prone to information disclosure.
Description
The 'favicon.ico' file found on the remote web server belongs to a popular web server. This may be used to fingerprint the web server.
Solution
Remove the 'favicon.ico' file or create a custom one for your site.
Risk Factor
None
Plugin Information
Published: 2005/10/28, Modified: 2020/06/12
Plugin Output

tcp/51528/www


MD5 fingerprint : 4644f2d45601037b8423d45e13194c93
Web server : Apache Tomcat or Alfresco Community

20108 - Web Server / Application favicon.ico Vendor Fingerprinting
-
Synopsis
The remote web server contains a graphic image that is prone to information disclosure.
Description
The 'favicon.ico' file found on the remote web server belongs to a popular web server. This may be used to fingerprint the web server.
Solution
Remove the 'favicon.ico' file or create a custom one for your site.
Risk Factor
None
Plugin Information
Published: 2005/10/28, Modified: 2020/06/12
Plugin Output

tcp/51529/www


MD5 fingerprint : 4644f2d45601037b8423d45e13194c93
Web server : Apache Tomcat or Alfresco Community

11422 - Web Server Unconfigured - Default Install Page Present
-
Synopsis
The remote web server is not configured or is improperly configured.
Description
The remote web server uses its default welcome page. Therefore, it's probable that this server is not used at all or is serving content that is meant to be hidden.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 2003/03/20, Modified: 2018/08/15
Plugin Output

tcp/51528/www


The default welcome page is from Tomcat.

11422 - Web Server Unconfigured - Default Install Page Present
-
Synopsis
The remote web server is not configured or is improperly configured.
Description
The remote web server uses its default welcome page. Therefore, it's probable that this server is not used at all or is serving content that is meant to be hidden.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 2003/03/20, Modified: 2018/08/15
Plugin Output

tcp/51529/www


The default welcome page is from Tomcat.

92436 - WinRAR History
-
Synopsis
Nessus was able to enumerate files opened with WinRAR on the remote host.
Description
Nessus was able to gather evidence of compressed files that were opened by WinRAR. Note that only compressed files that were opened and not extracted through the explorer shortcut or command line interface were reported.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

Z:\RMS\ODIN\2025\DEC\1312\13122025072647.zip
C:\Users\Administrator\Desktop\20122025\VAR121225 (3).zip
Z:\RMS\ODIN\2025\DEC\2012\19122025093245.zip
D:\XTPL\APPS\UAT\xHawkeye Server 2.2.0.39\Downloads\rename.zip

WinRAR report attached.

162174 - Windows Always Installed Elevated Status
-
Synopsis
Windows AlwaysInstallElevated policy status was found on the remote Windows host
Description
Windows AlwaysInstallElevated policy status was found on the remote Windows host.
You can use the AlwaysInstallElevated policy to install a Windows Installer package with elevated (system) privileges This option is equivalent to granting full administrative rights, which can pose a massive security risk. Microsoft strongly discourages the use of this setting.
Solution
If enabled, disable AlwaysInstallElevated policy per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/06/14, Modified: 2022/06/14
Plugin Output

tcp/445/cifs

AlwaysInstallElevated policy is not enabled under HKEY_LOCAL_MACHINE.
AlwaysInstallElevated policy is not enabled under HKEY_USERS user:S-1-5-21-3119273522-2427777209-1705870880-500

48337 - Windows ComputerSystemProduct Enumeration (WMI)
-
Synopsis
It is possible to obtain product information from the remote host using WMI.
Description
By querying the WMI class 'Win32_ComputerSystemProduct', it is possible to extract product information about the computer system such as UUID, IdentifyingNumber, vendor, etc.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/08/16, Modified: 2025/12/15
Plugin Output

tcp/0


+ Computer System Product
- IdentifyingNumber : SGH437N_DX
- Description : Computer System Product
- Vendor : HP
- Name : ProLiant DL360p Gen8
- UUID : 30343536-3138-4753-4834-33374E5F4458

159817 - Windows Credential Guard Status
-
Synopsis
Retrieves the status of Windows Credential Guard.
Description
Retrieves the status of Windows Credential Guard.
Credential Guard prevents attacks such as such as Pass-the-Hash or Pass-The-Ticket by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/04/18, Modified: 2023/08/25
Plugin Output

tcp/445/cifs


Windows Credential Guard is not fully enabled.
The following registry keys have not been set :
- System\CurrentControlSet\Control\DeviceGuard\RequirePlatformSecurityFeatures : Key not found.
- System\CurrentControlSet\Control\LSA\LsaCfgFlags : Key not found.
- System\CurrentControlSet\Control\DeviceGuard\EnableVirtualizationBasedSecurity : Key not found.
58181 - Windows DNS Server Enumeration
-
Synopsis
Nessus enumerated the DNS servers being used by the remote Windows host.
Description
Nessus was able to enumerate the DNS servers configured on the remote Windows host by looking in the registry.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/03/01, Modified: 2022/02/01
Plugin Output

tcp/445/cifs


Nessus enumerated DNS servers for the following interfaces :

Interface: {a83edb03-f7dd-4ff9-b5cc-3a1809468fe3}
Network Connection : LAN_73
NameServer: 8.8.8.8,4.2.2.2
164690 - Windows Disabled Command Prompt Enumeration
-
Synopsis
This plugin determines if the DisableCMD policy is enabled or disabled on the remote host for each local user.
Description
The remote host may employ the DisableCMD policy on a per user basis. Enumerated local users may have the following registry key:
'HKLM\Software\Policies\Microsoft\Windows\System\DisableCMD'

- Unset or 0: The command prompt is enabled normally.
- 1: The command promt is disabled.
- 2: The command prompt is disabled however windows batch processing is allowed.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2022/09/06, Modified: 2022/10/05
Plugin Output

tcp/445/cifs


Username: tidua
SID: S-1-5-21-3119273522-2427777209-1705870880-1006
DisableCMD: Unset

Username: LKPAdmin
SID: S-1-5-21-3119273522-2427777209-1705870880-1005
DisableCMD: Unset

Username: DefaultAccount
SID: S-1-5-21-3119273522-2427777209-1705870880-503
DisableCMD: Unset

Username: Production
SID: S-1-5-21-3119273522-2427777209-1705870880-500
DisableCMD: Unset

Username: Guest
SID: S-1-5-21-3119273522-2427777209-1705870880-501
DisableCMD: Unset

72482 - Windows Display Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the display drivers on the remote host.
Description
Nessus was able to enumerate one or more of the display drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0756
Plugin Information
Published: 2014/02/06, Modified: 2025/12/15
Plugin Output

tcp/0


Device Name : Microsoft Basic Display Adapter
Driver File Version : 10.0.14393.0
Driver Date : 06/21/2006
Video Processor : Matrox Graphics Inc.
171956 - Windows Enumerate Accounts
-
Synopsis
Enumerate Windows accounts.
Description
Enumerate Windows accounts.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2023/02/28, Modified: 2025/12/15
Plugin Output

tcp/0

Windows accounts enumerated. Results output to DB.
User data gathered in scan starting at : 2026/1/10 5:02 India Standard Time
92423 - Windows Explorer Recently Executed Programs
-
Synopsis
Nessus was able to enumerate recently executed programs on the remote host.
Description
Nessus was able to find evidence of program execution using Windows Explorer registry logs and settings.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2019/08/15
Plugin Output

tcp/0

xHawkEyeServer.exePO :i+00/D:\N1zYQiXTPL:XM"ZV\r.XTPLN1Y^APPS:XM"ZV\r.FAPPSJ1Ya`UAT8+Yb"ZV\r.k"UAT1YUxHawkeye Server 2.2.0.39d+Yb"ZV\r.wL,xHawkeye Server 2.2.0.39(\1#Z]7DownloadsD+Yb#Z]7.8xDownloads
{55101DA3-3621-49A9-A970-7776FD86DBE9}PO :i+00/D:\N1[T7XTPL:XM'\C\r.XTPLN1[:APPS:XM'\C\r.0APPSJ1H[+UAT8+Yb'\C\r.k\mUAT1[RxHawkeye Server 2.2.0.39d+Yb'\C\r.w@xHawkeye Server 2.2.0.39(\1'\YDownloadsD+Yb'\Y.8xgDownloads
ConfigEditor - Copy.exePO :i+00/D:\N1-YVXTPL:XM-YV.VyXTPLN1+YbAPPS:XM+Yb.H2]APPS1$Y5xHawkeye Server 2.2.0.38d$Y5$Y5.eLhxHawkeye Server 2.2.0.38(T1mYConfig>$Y5mY.ECConfigf1mYEYConfigEditorJ$Y5mYEY.ConfigEditor
Ssms.exePO :i+00.+ezFkp:1M[\nSQLSER~1jX;A[.r'6SQL Server Management Studio
SanerNow_Windows_x86_6.3.exePO :i+00/D:\V1YtLKPSOFT@XQYt.#LKPSOFT1YvSanerNow_LKP_Window_CM_Windows_x86_6.3~YtYv.J;\r?SanerNow_LKP_Window_CM_Windows_x86_6.36
\r\n
xHawkEyeClient.exePO :i+00/Z:\J1G[RMS8YO)j[g.RMS\1+[eSTWT4K~UDL\j[M.)AsurvlimitN1k[L[2025:YQk[M[.u2025
chrome.exePO :i+00.9#K&]B_
mspaint.exePO :i+00/Z:\
InetMgr.exePO :i+00/D:\V1XYLKPSOFT@XQXY.#NbLKPSOFT
{85EF815B-4998-48B6-891B-B4B5DEA14BF2}PO :i+00:.:,LB)A&&BVZ1kZYPuploaderBkZkOmZ;.2oTH\uploader
OpenWith.exePO :i+00/C:\p1lZPROGRA~2XH0mZF.'gProgram Files (x86)j1Ye,0MIF5BA~1RY+mZA.PMicrosoft OfficeZ1Y,0Office14BY+mZA.PH/Office14
ConfigEditor.exePO :i+00/D:\N1ZlXTPL:XMH[)..XTPLN1fZAAPPS:XMH[+.BAPPSJ1H[+UAT8+YbH[+.k\mUAT1H[+xHawkeye Server 06102025bH[+H[+.`!\mxHawkeye Server 06102025(1F[^xHawkeye Server 06102025bH[+H[+.`%xHawkeye Server 06102025(1H[Y,xHawkeye Server 25.0.8.20 - CopyrH[+H[Y,.`$xHawkeye Server 25.0.8.20 - Copy0T1H[p-Config>H[+H[p-.@`G`Config
notepad.exePO :i+00.:,LB)A
notepad++.exePO :i+00.:,LB)A
\\192.168.10.172\d$\1
\\192.168.10.80\d$\1
dcomcnfg\1
notepad\1
regedit\1
winver\1
mstsc\1
rdpclip.exe\1
\\192.168.10.184\d$\1
\\192.168.10.234\1
excel\1
cmd\1
\\172.17.100.224\1
\\192.168.10.176\d$\1
\\172.17.100.222\1
services.msc\1
\\172.17.100.88\d$\1
ncpa.cpl\1
wmimgmt.msc\1
dxdiag\1
ixvbsutldrmkjnefywpcgzaqho
\\192.168.10.177\d$\1
calc\1
appwiz.cpl\1
\\192.168.10.174\d$\1
\\172.17.100.91\1
\\192.168.10.235\1
xHawkEyeServer.exe^
{55101DA3-3621-49A9-A970-7776FD86DBE9}^
ConfigEditor - Copy.exed
SanerNow_Windows_x86_6.3.exe/]
\r\n
OpenWith.exe
xHawkEyeClient.exe^
chrome.exe^,
mspaint.exeN`b
Explorer.EXE
InetMgr.exeeV
{85EF815B-4998-48B6-891B-B4B5DEA14BF2}^
ConfigEditor.exe^
Ssms.exe^%
notepad.exe`
notepad++.exe^+
X\r,!PCsg<
x@_dP/N

MRU programs details in attached report.
92418 - Windows Explorer Typed Paths
-
Synopsis
Nessus was able to enumerate the directory paths that users visited by typing the full directory path into Windows Explorer.
Description
Nessus was able to enumerate the directory paths that users visited by manually typing the full directory path into Windows Explorer. The generated folder list report contains folders local to the system, folders from past mounted network drives, and folders from mounted devices.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

D:\XTPL\Pledge Tomcat\apache-tomcat-9.0.104
D:\xtpl
C:\Users\Administrator\Documents
D:\XTPL\APPS\UAT\xHawkeye client 2.2.0.39\FileData
D:\XTPL\Tomcat
D:\XTPL\Allocation_EarlyPayin\New exe\errorLog
Desktop
D:\XTPL\APPS\UAT\xHawkeye Server 2.2.0.39\Downloads
Z:\RMS\allocation\2024\NOV 2024
C:\Users\Administrator\Desktop\peak
D:\xtpl\apps
D:\XTPL\APPS\UAT\xHawkeye Server 2.2.0.39\logs
cmd
D:\XTPL\APPS\xHawkeye Server 2.2.0.38\Downloads
Documents
\\192.168.150.179\d$
Z:\rms
C:\Users\Administrator\Desktop\uploader
D:\xtpl\apps\uat
CMD
C:\Users\Administrator\Desktop\mtf
D:\XTPL\APPS\xHawkeye Server_1.0.0.207\Downloads
C:\Users\Administrator\Desktop
D:\XTPL\APPS\UAT\xHawkeye Server 2.2.0.39
D:\XTPL\Allocation_EarlyPayin

Extended explorer typed paths report attached.

159929 - Windows LSA Protection Status
-
Synopsis
Windows LSA Protection is disabled on the remote Windows host.
Description
The LSA Protection validates users for local and remote sign-ins and enforces local security policies to prevent reading memory and code injection by non-protected processes. This provides added security for the credentials that the LSA stores and manages. This protects against Pass-the-Hash or Mimikatz-style attacks.
Solution
Enable LSA Protection per your corporate security guidelines.
Risk Factor
None
Plugin Information
Published: 2022/04/20, Modified: 2025/06/16
Plugin Output

tcp/445/cifs


LSA Protection Key \SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL not found.

148541 - Windows Language Settings Detection
-
Synopsis
This plugin enumerates language files on a windows host.
Description
By connecting to the remote host with the supplied credentials, this plugin enumerates language IDs listed on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/04/14, Modified: 2022/02/01
Plugin Output

tcp/0

Default Install Language Code: 1033

Default Active Language Code: 1033

Other common microsoft Language packs may be scanned as well.
92422 - Windows Mapped Network Drives
-
Synopsis
Nessus was able to enumerate mapped network drives on the remote host.
Description
Nessus was able to generate a report of mapped network drives on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/11/15
Plugin Output

tcp/0

j : \\172.17.100.91\Rtrade
b : \\172.17.100.187\xtpl
d : \\172.17.100.61\Rtrade
e : \\192.168.10.177\d\XTS\TWS\TWS_x64\AppData\LKP\ADMIN\OTB
g : \\172.17.100.61\e$\DBbackup
i : \\172.17.100.91\Rtrade$
a : \\172.17.100.222\Common
mrulist : ahjigfedcb
f : \\172.17.100.184\trade\OTB
h : \\172.17.100.91\c$\Program Files (x86)\Tata Consultancy Services\Member Control Station(MCS)\DATA\56630\Rtrade
c : \\172.17.100.51\otd


Extended mapped network drive report attached.

10150 - Windows NetBIOS / SMB Remote Host Information Disclosure
-
Synopsis
It was possible to obtain the network name of the remote host.
Description
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.

Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output

udp/137/netbios-ns

The following 3 NetBIOS names have been gathered :

XHWAKEYESRV = File Server Service
XHWAKEYESRV = Computer name
WORKGROUP = Workgroup / Domain name

The remote host has the following MAC address on its adapter :

40:a8:f0:20:84:35

155963 - Windows Printer Driver Enumeration
-
Synopsis
Nessus was able to enumerate one or more of the printer drivers on the remote host.
Description
Nessus was able to enumerate one or more of the printer drivers on the remote host via WMI.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/12/09, Modified: 2025/12/15
Plugin Output

tcp/445/cifs


--- Microsoft XPS Document Writer v4 ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_3d8f0626c408afea\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Send To Microsoft OneNote 2010 Driver ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 0.0.0.0
Supported Platform : Windows x64

--- HP LaserJet M3035 MFP PCL6 Class Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_3d8f0626c408afea\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Samsung M267x 287x Series Class Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_3d8f0626c408afea\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Microsoft enhanced Point and Print compatibility driver ---

Nessus detected 2 installs of Microsoft enhanced Point and Print compatibility driver:

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.14393.1198
Supported Platform : Windows x64

Path : C:\Windows\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll
Version : 10.0.14393.1198
Supported Platform : Windows NT x86

--- Microsoft Print To PDF ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_3d8f0626c408afea\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- HP LaserJet P205X series PCL6 Class Driver ---

Path : C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_3d8f0626c408afea\Amd64\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Microsoft Shared Fax Driver ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
Version : 10.0.14393.0
Supported Platform : Windows x64

--- Remote Desktop Easy Print ---

Path : C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
Version : 10.0.14393.0
Supported Platform : Windows x64
63620 - Windows Product Key Retrieval
-
Synopsis
This plugin retrieves the Windows Product key of the remote Windows host.
Description
Using the supplied credentials, Nessus was able to obtain the retrieve the Windows host's partial product key'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/01/18, Modified: 2013/01/18
Plugin Output

tcp/445/cifs


Product key : XXXXX-XXXXX-XXXXX-XXXXX-C38T7

Note that all but the final portion of the key has been obfuscated.
160576 - Windows Services Registry ACL
-
Synopsis
Checks Windows Registry for Service ACLs
Description
Checks Windows Registry for Service ACLs.
Solution
N/A
Risk Factor
None
Plugin Information
Published: 2022/05/05, Modified: 2024/01/15
Plugin Output

tcp/445/cifs

report output too big - ending list here

85736 - Windows Store Application Enumeration
-
Synopsis
It is possible to obtain the list of applications installed from the Windows Store.
Description
This plugin connects to the remote Windows host with the supplied credentials and uses WMI and Powershell to enumerate applications installed on the host from the Windows Store.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/09/02, Modified: 2025/12/15
Plugin Output

tcp/0


-Microsoft.AAD.BrokerPlugin
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.BioEnrollment
Version : 10.0.14393.0
InstallLocation : C:\Windows\SystemApps\Microsoft.BioEnrollment_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.CloudExperienceHost
Version : 10.0.14393.1066
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Cortana
Version : 1.7.0.14393
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.SecondaryTileExperience
Version : 10.0.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.SecondaryTileExperience_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.XboxGameCallableUI
Version : 1000.14393.0.0
InstallLocation : C:\Windows\SystemApps\Microsoft.XboxGameCallableUI_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-windows.immersivecontrolpanel
Version : 6.2.0.0
InstallLocation : C:\Windows\ImmersiveControlPanel
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.MiracastView
Version : 6.3.0.0
InstallLocation : C:\Windows\MiracastView
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Windows.PrintDialog
Version : 6.2.0.0
InstallLocation : C:\Windows\PrintDialog
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.ShellExperienceHost
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.AccountsControl
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.LockApp
Version : 10.0.14393.2068
InstallLocation : C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.Apprep.ChxApp
Version : 1000.14393.2273.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

-Microsoft.Windows.AssignedAccessLockApp
Version : 1000.14393.2068.0
InstallLocation : C:\Windows\SystemApps\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
Architecture : Neutral
Publisher : CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
204960 - Windows System Driver Enumeration (Windows)
-
Synopsis
One or more kernel or file system drivers were enumerated on the remote Windows host.
Description
One or more kernel or file system drivers were enumerated on the remote Windows host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2024/08/01, Modified: 2025/12/15
Plugin Output

tcp/0


Total : 317

Name : 1394ohci
Path : C:\Windows\system32\drivers\1394ohci.sys
Service Type : Kernel Driver
Description : 1394 OHCI Compliant Host Controller
State : Stopped

Name : 3ware
Path : C:\Windows\system32\drivers\3ware.sys
Service Type : Kernel Driver
Description : 3ware
State : Stopped

Name : ACPI
Path : C:\Windows\system32\drivers\ACPI.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Driver
State : Running

Name : AcpiDev
Path : C:\Windows\system32\drivers\AcpiDev.sys
Service Type : Kernel Driver
Description : ACPI Devices driver
State : Stopped

Name : acpiex
Path : C:\Windows\system32\Drivers\acpiex.sys
Service Type : Kernel Driver
Description : Microsoft ACPIEx Driver
State : Running

Name : acpipagr
Path : C:\Windows\system32\drivers\acpipagr.sys
Service Type : Kernel Driver
Description : ACPI Processor Aggregator Driver
State : Stopped

Name : AcpiPmi
Path : C:\Windows\system32\drivers\acpipmi.sys
Service Type : Kernel Driver
Description : ACPI Power Meter Driver
State : Running

Name : acpitime
Path : C:\Windows\system32\drivers\acpitime.sys
Service Type : Kernel Driver
Description : ACPI Wake Alarm Driver
State : Stopped

Name : ADP80XX
Path : C:\Windows\system32\drivers\ADP80XX.SYS
Service Type : Kernel Driver
Description : ADP80XX
State : Stopped

Name : AFD
Path : C:\Windows\system32\drivers\afd.sys
Service Type : Kernel Driver
Description : Ancillary Function Driver for Winsock
State : Running

Name : ahcache
Path : C:\Windows\system32\DRIVERS\ahcache.sys
Service Type : Kernel Driver
Description : Application Compatibility Cache
State : Running

Name : AmdK8
Path : C:\Windows\system32\drivers\amdk8.sys
Service Type : Kernel Driver
Description : AMD K8 Processor Driver
State : Stopped

Name : AmdPPM
Path : C:\Windows\system32\drivers\amdppm.sys
Service Type : Kernel Driver
Description : AMD Processor Driver
State : Stopped

Name : amdsata
Path : C:\Windows\system32\drivers\amdsata.sys
Service Type : Kernel Driver
Description : amdsata
State : Stopped

Name : amdsbs
Path : C:\Windows\system32\drivers\amdsbs.sys
Service Type : Kernel Driver
Description : amdsbs
State : Stopped

Name : amdxata
Path : C:\Windows\system32\drivers\amdxata.sys
Service Type : Kernel Driver
Description : amdxata
State : Stopped

Name : AppID
Path : C:\Windows\system32\drivers\appid.sys
Service Type : Kernel Driver
Description : AppID Driver
State : Stopped

Name : applockerfltr
Path : C:\Windows\system32\drivers\applockerfltr.sys
Service Type : Kernel Driver
Description : Smartlocker Filter Driver
State : Stopped

Name : AppvStrm
Path : C:\Windows\system32\drivers\AppvStrm.sys
Service Type : File System Driver
Description : AppvStrm
State : Stopped

Name : AppvVemgr
Path : C:\Windows\system32\drivers\AppvVemgr.sys
Service Type : File System Driver
Description : AppvVemgr
State : Stopped

Name : AppvVfs
Path : C:\Windows\system32\drivers\AppvVfs.sys
Service Type : File System Driver
Description : AppvVfs
State : Stopped

Name : arcsas
Path : C:\Windows\system32\drivers\arcsas.sys
Service Type : Kernel Driver
Description : Adaptec SAS/SATA-II RAID Storport's Miniport Driver
State : Stopped

Name : AsyncMac
Path : C:\Windows\system32\drivers\asyncmac.sys
Service Type : Kernel Driver
Description : RAS Asynchronous Media Driver
State : Stopped

Name : atapi
Path : C:\Windows\system32\drivers\atapi.sys
Service Type : Kernel Driver
Description : IDE Channel
State : Running

Name : b06bdrv
Path : C:\Windows\system32\drivers\bxvbda.sys
Service Type : Kernel Driver
Description : QLogic Network Adapter VBD
State : Stopped

Name : b57nd60a
Path : C:\Windows\system32\drivers\b57nd60a.sys
Service Type : Kernel Driver
Description : Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
State : Running

Name : BasicDisplay
Path : C:\Windows\system32\drivers\BasicDisplay.sys
Service Type : Kernel Driver
Description : BasicDisplay
State : Running

Name : BasicRender
Path : C:\Windows\system32\drivers\BasicRender.sys
Service Type : Kernel Driver
Description : BasicRender
State : Running

Name : bcmfn
Path : C:\Windows\system32\drivers\bcmfn.sys
Service Type : Kernel Driver
Description : bcmfn Service
State : Stopped

Name : bcmfn2
Path : C:\Windows\system32\drivers\bcmfn2.sys
Service Type : Kernel Driver
Description : bcmfn2 Service
State : Stopped

Name : Beep
Path : C:\Windows\system32\drivers\Beep.sys
Service Type : Kernel Driver
Description : Beep
State : Stopped

Name : bfadfcoei
Path : C:\Windows\system32\drivers\bfadfcoei.sys
Service Type : Kernel Driver
Description : bfadfcoei
State : Stopped

Name : bfadi
Path : C:\Windows\system32\drivers\bfadi.sys
Service Type : Kernel Driver
Description : bfadi
State : Stopped

Name : bowser
Path : C:\Windows\system32\DRIVERS\bowser.sys
Service Type : File System Driver
Description : Browser Support Driver
State : Running

Name : buttonconverter
Path : C:\Windows\system32\drivers\buttonconverter.sys
Service Type : Kernel Driver
Description : Service for Portable Device Control devices
State : Stopped

Name : bxfcoe
Path : C:\Windows\system32\drivers\bxfcoe.sys
Service Type : Kernel Driver
Description : QLogic FCoE Offload driver
State : Stopped

Name : bxois
Path : C:\Windows\system32\drivers\bxois.sys
Service Type : Kernel Driver
Description : QLogic Offload iSCSI Driver
State : Stopped

Name : CapImg
Path : C:\Windows\system32\drivers\capimg.sys
Service Type : Kernel Driver
Description : HID driver for CapImg touch screen
State : Stopped

Name : cdfs
Path : C:\Windows\system32\DRIVERS\cdfs.sys
Service Type : File System Driver
Description : CD/DVD File System Reader
State : Stopped

Name : cdrom
Path : C:\Windows\system32\drivers\cdrom.sys
Service Type : Kernel Driver
Description : CD-ROM Driver
State : Stopped

Name : cht4iscsi
Path : C:\Windows\system32\drivers\cht4sx64.sys
Service Type : Kernel Driver
Description : cht4iscsi
State : Stopped

Name : cht4vbd
Path : C:\Windows\system32\drivers\cht4vx64.sys
Service Type : Kernel Driver
Description : Chelsio Virtual Bus Driver
State : Stopped

Name : CLFS
Path : C:\Windows\system32\drivers\CLFS.sys
Service Type : Kernel Driver
Description : Common Log (CLFS)
State : Running

Name : clreg
Path : C:\Windows\system32\drivers\registry.sys
Service Type : Kernel Driver
Description : Virtual Registry for Containers
State : Running

Name : CmBatt
Path : C:\Windows\system32\drivers\CmBatt.sys
Service Type : Kernel Driver
Description : Microsoft ACPI Control Method Battery Driver
State : Stopped

Name : CNG
Path : C:\Windows\system32\Drivers\cng.sys
Service Type : Kernel Driver
Description : CNG
State : Running

Name : cnghwassist
Path : C:\Windows\system32\DRIVERS\cnghwassist.sys
Service Type : Kernel Driver
Description : CNG Hardware Assist algorithm provider
State : Stopped

Name : CompositeBus
Path : C:\Windows\system32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
Service Type : Kernel Driver
Description : Composite Bus Enumerator Driver
State : Running

Name : condrv
Path : C:\Windows\system32\drivers\condrv.sys
Service Type : Kernel Driver
Description : Console Driver
State : Running

Name : CSC
Path : C:\Windows\system32\drivers\csc.sys
Service Type : Kernel Driver
Description : Offline Files Driver
State : Stopped

Name : dam
Path : C:\Windows\system32\drivers\dam.sys
Service Type : Kernel Driver
Description : Desktop Activity Moderator Driver
State : Stopped

Name : Dfsc
Path : C:\Windows\system32\Drivers\dfsc.sys
Service Type : File System Driver
Description : DFS Namespace Client Driver
State : Running

Name : Disk
Path : C:\Windows\system32\drivers\disk.sys
Service Type : Kernel Driver
Description : Disk Driver
State : Running

Name : dmvsc
Path : C:\Windows\system32\drivers\dmvsc.sys
Service Type : Kernel Driver
Description : dmvsc
State : Stopped

Name : DXGKrnl
Path : C:\Windows\system32\drivers\dxgkrnl.sys
Service Type : Kernel Driver
Description : LDDM Graphics Subsystem
State : Running

Name : ebdrv
Path : C:\Windows\system32\drivers\evbda.sys
Service Type : Kernel Driver
Description : QLogic 10 Gigabit Ethernet Adapter VBD
State : Stopped

Name : EhStorClass
Path : C:\Windows\system32\drivers\EhStorClass.sys
Service Type : Kernel Driver
Description : Enhanced Storage Filter Driver
State : Running

Name : EhStorTcgDrv
Path : C:\Windows\system32\drivers\EhStorTcgDrv.sys
Service Type : Kernel Driver
Description : Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols
State : Stopped

Name : elxfcoe
Path : C:\Windows\system32\drivers\elxfcoe.sys
Service Type : Kernel Driver
Description : elxfcoe
State : Stopped

Name : elxstor
Path : C:\Windows\system32\drivers\elxstor.sys
Service Type : Kernel Driver
Description : elxstor
State : Stopped

Name : ErrDev
Path : C:\Windows\system32\drivers\errdev.sys
Service Type : Kernel Driver
Description : Microsoft Hardware Error Device Driver
State : Stopped

Name : exfat
Path : C:\Windows\system32\drivers\exfat.sys
Service Type : File System Driver
Description : exFAT File System Driver
State : Stopped

Name : fastfat
Path : C:\Windows\system32\drivers\fastfat.sys
Service Type : File System Driver
Description : FAT12/16/32 File System Driver
State : Stopped

Name : fcvsc
Path : C:\Windows\system32\drivers\fcvsc.sys
Service Type : Kernel Driver
Description : fcvsc
State : Stopped

Name : fdc
Path : C:\Windows\system32\drivers\fdc.sys
Service Type : Kernel Driver
Description : Floppy Disk Controller Driver
State : Stopped

Name : FileCrypt
Path : C:\Windows\system32\drivers\filecrypt.sys
Service Type : File System Driver
Description : FileCrypt
State : Running

Name : FileInfo
Path : C:\Windows\system32\drivers\fileinfo.sys
Service Type : File System Driver
Description : File Information FS MiniFilter
State : Stopped

Name : Filetrace
Path : C:\Windows\system32\drivers\filetrace.sys
Service Type : File System Driver
Description : Filetrace
State : Stopped

Name : flpydisk
Path : C:\Windows\system32\drivers\flpydisk.sys
Service Type : Kernel Driver
Description : Floppy Disk Driver
State : Stopped

Name : FltMgr
Path : C:\Windows\system32\drivers\fltmgr.sys
Service Type : File System Driver
Description : FltMgr
State : Running

Name : FsDepends
Path : C:\Windows\system32\drivers\FsDepends.sys
Service Type : File System Driver
Description : File System Dependency Minifilter
State : Stopped

Name : gencounter
Path : C:\Windows\system32\drivers\vmgencounter.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Generation Counter
State : Stopped

Name : genericusbfn
Path : C:\Windows\system32\drivers\genericusbfn.sys
Service Type : Kernel Driver
Description : Generic USB Function Class
State : Stopped

Name : GPIOClx0101
Path : C:\Windows\system32\Drivers\msgpioclx.sys
Service Type : Kernel Driver
Description : Microsoft GPIO Class Extension Driver
State : Stopped

Name : GpuEnergyDrv
Path : C:\Windows\system32\drivers\gpuenergydrv.sys
Service Type : Kernel Driver
Description : GPU Energy Driver
State : Running

Name : HDAudBus
Path : C:\Windows\system32\drivers\HDAudBus.sys
Service Type : Kernel Driver
Description : Microsoft UAA Bus Driver for High Definition Audio
State : Stopped

Name : HidBatt
Path : C:\Windows\system32\drivers\HidBatt.sys
Service Type : Kernel Driver
Description : HID UPS Battery Driver
State : Stopped

Name : HidBth
Path : C:\Windows\system32\drivers\hidbth.sys
Service Type : Kernel Driver
Description : Microsoft Bluetooth HID Miniport
State : Stopped

Name : hidinterrupt
Path : C:\Windows\system32\drivers\hidinterrupt.sys
Service Type : Kernel Driver
Description : Common Driver for HID Buttons implemented with interrupts
State : Stopped

Name : HidUsb
Path : C:\Windows\system32\drivers\hidusb.sys
Service Type : Kernel Driver
Description : Microsoft HID Class Driver
State : Stopped

Name : HpSAMD
Path : C:\Windows\system32\drivers\HpSAMD.sys
Service Type : Kernel Driver
Description : HpSAMD
State : Running

Name : HTTP
Path : C:\Windows\system32\drivers\HTTP.sys
Service Type : Kernel Driver
Description : HTTP Service
State : Running

Name : hvservice
Path : C:\Windows\system32\drivers\hvservice.sys
Service Type : Kernel Driver
Description : Hypervisor/Virtual Machine Support Driver
State : Stopped

Name : hwpolicy
Path : C:\Windows\system32\drivers\hwpolicy.sys
Service Type : Kernel Driver
Description : Hardware Policy Driver
State : Stopped

Name : hyperkbd
Path : C:\Windows\system32\drivers\hyperkbd.sys
Service Type : Kernel Driver
Description : hyperkbd
State : Stopped

Name : HyperVideo
Path : C:\Windows\system32\drivers\HyperVideo.sys
Service Type : Kernel Driver
Description : HyperVideo
State : Stopped

Name : i8042prt
Path : C:\Windows\system32\drivers\i8042prt.sys
Service Type : Kernel Driver
Description : i8042 Keyboard and PS/2 Mouse Port Driver
State : Stopped

Name : iaLPSSi_GPIO
Path : C:\Windows\system32\drivers\iaLPSSi_GPIO.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO GPIO Controller Driver
State : Stopped

Name : iaLPSSi_I2C
Path : C:\Windows\system32\drivers\iaLPSSi_I2C.sys
Service Type : Kernel Driver
Description : Intel(R) Serial IO I2C Controller Driver
State : Stopped

Name : iaStorAV
Path : C:\Windows\system32\drivers\iaStorAV.sys
Service Type : Kernel Driver
Description : Intel(R) SATA RAID Controller Windows
State : Stopped

Name : iaStorV
Path : C:\Windows\system32\drivers\iaStorV.sys
Service Type : Kernel Driver
Description : Intel RAID Controller Windows 7
State : Stopped

Name : ibbus
Path : C:\Windows\system32\drivers\ibbus.sys
Service Type : Kernel Driver
Description : Mellanox InfiniBand Bus/AL (Filter Driver)
State : Stopped

Name : IndirectKmd
Path : C:\Windows\system32\drivers\IndirectKmd.sys
Service Type : Kernel Driver
Description : Indirect Displays Kernel-Mode Driver
State : Stopped

Name : intelide
Path : C:\Windows\system32\drivers\intelide.sys
Service Type : Kernel Driver
Description : intelide
State : Stopped

Name : intelpep
Path : C:\Windows\system32\drivers\intelpep.sys
Service Type : Kernel Driver
Description : Intel(R) Power Engine Plug-in Driver
State : Running

Name : intelppm
Path : C:\Windows\system32\drivers\intelppm.sys
Service Type : Kernel Driver
Description : Intel Processor Driver
State : Running

Name : IpFilterDriver
Path : C:\Windows\system32\DRIVERS\ipfltdrv.sys
Service Type : Kernel Driver
Description : IP Traffic Filter Driver
State : Stopped

Name : IPMIDRV
Path : C:\Windows\system32\drivers\IPMIDrv.sys
Service Type : Kernel Driver
Description : IPMIDRV
State : Stopped

Name : IPNAT
Path : C:\Windows\system32\drivers\ipnat.sys
Service Type : Kernel Driver
Description : IP Network Address Translator
State : Stopped

Name : IPsecGW
Path : C:\Windows\system32\drivers\ipsecgw.sys
Service Type : Kernel Driver
Description : Windows IPsec Gateway Driver
State : Stopped

Name : isapnp
Path : C:\Windows\system32\drivers\isapnp.sys
Service Type : Kernel Driver
Description : isapnp
State : Stopped

Name : iScsiPrt
Path : C:\Windows\system32\drivers\msiscsi.sys
Service Type : Kernel Driver
Description : iScsiPort Driver
State : Stopped

Name : kbdclass
Path : C:\Windows\system32\drivers\kbdclass.sys
Service Type : Kernel Driver
Description : Keyboard Class Driver
State : Running

Name : kbdhid
Path : C:\Windows\system32\drivers\kbdhid.sys
Service Type : Kernel Driver
Description : Keyboard HID Driver
State : Stopped

Name : kdnic
Path : C:\Windows\system32\drivers\kdnic.sys
Service Type : Kernel Driver
Description : Microsoft Kernel Debug Network Miniport (NDIS 6.20)
State : Running

Name : klbackupdisk.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupdisk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klbackupdisk.KES-21-15
State : Running

Name : klbackupflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klbackupflt.sys
Service Type : File System Driver
Description : Kaspersky Lab klbackupflt.KES-21-15
State : Running

Name : klelam
Path : C:\Windows\system32\DRIVERS\klelam.sys
Service Type : Kernel Driver
Description : klelam
State : Stopped

Name : KLFLT.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab Kernel DLL.KES-21-15
State : Running

Name : klfltdev.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klfltdev.sys
Service Type : Kernel Driver
Description : Kaspersky Lab KLFltDev.KES-21-15
State : Running

Name : klgse.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klgse.sys
Service Type : File System Driver
Description : Kaspersky Lab Security Extender Driver.KES-21-15
State : Running

Name : KLHK.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klhk.sys
Service Type : Kernel Driver
Description : Kaspersky Lab service driver.KES-21-15
State : Running

Name : KLIF.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klif.sys
Service Type : File System Driver
Description : Kaspersky Lab Driver.KES-21-15
State : Running

Name : klim6
Path : C:\Windows\system32\DRIVERS\klim6.sys
Service Type : Kernel Driver
Description : Kaspersky Anti-Virus NDIS 6 Filter
State : Running

Name : klpd.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpd.sys
Service Type : File System Driver
Description : Kaspersky Lab format recognizer driver.KES-21-15
State : Running

Name : klpnpflt.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klpnpflt.sys
Service Type : Kernel Driver
Description : Kaspersky Lab klpnpflt.KES-21-15
State : Running

Name : klupd_KES-21-15_arkmon
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_arkmon.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_arkmon
State : Running

Name : klupd_KES-21-15_klark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klark
State : Running

Name : klupd_KES-21-15_klbg
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_klbg.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_klbg
State : Running

Name : klupd_KES-21-15_mark
Path : C:\Windows\system32\Drivers\klupd_KES-21-15_mark.sys
Service Type : Kernel Driver
Description : klupd_KES-21-15_mark
State : Running

Name : klwfp
Path : C:\Windows\system32\DRIVERS\klwfp.sys
Service Type : Kernel Driver
Description : klwfp
State : Running

Name : klwtp.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\klwtp.sys
Service Type : Kernel Driver
Description : klwtp.KES-21-15
State : Running

Name : kneps.KES-21-15
Path : C:\Windows\system32\DRIVERS\KES-21-15\kneps.sys
Service Type : Kernel Driver
Description : kneps.KES-21-15
State : Running

Name : KSecDD
Path : C:\Windows\system32\Drivers\ksecdd.sys
Service Type : Kernel Driver
Description : KSecDD
State : Running

Name : KSecPkg
Path : C:\Windows\system32\Drivers\ksecpkg.sys
Service Type : Kernel Driver
Description : KSecPkg
State : Running

Name : ksthunk
Path : C:\Windows\system32\drivers\ksthunk.sys
Service Type : Kernel Driver
Description : Kernel Streaming Thunks
State : Stopped

Name : lltdio
Path : C:\Windows\system32\drivers\lltdio.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Mapper I/O Driver
State : Running

Name : LSI_SAS
Path : C:\Windows\system32\drivers\lsi_sas.sys
Service Type : Kernel Driver
Description : LSI_SAS
State : Stopped

Name : LSI_SAS2i
Path : C:\Windows\system32\drivers\lsi_sas2i.sys
Service Type : Kernel Driver
Description : LSI_SAS2i
State : Stopped

Name : LSI_SAS3i
Path : C:\Windows\system32\drivers\lsi_sas3i.sys
Service Type : Kernel Driver
Description : LSI_SAS3i
State : Stopped

Name : LSI_SSS
Path : C:\Windows\system32\drivers\lsi_sss.sys
Service Type : Kernel Driver
Description : LSI_SSS
State : Stopped

Name : luafv
Path : C:\Windows\system32\drivers\luafv.sys
Service Type : File System Driver
Description : UAC File Virtualization
State : Running

Name : megasas
Path : C:\Windows\system32\drivers\megasas.sys
Service Type : Kernel Driver
Description : megasas
State : Stopped

Name : megasas2i
Path : C:\Windows\system32\drivers\MegaSas2i.sys
Service Type : Kernel Driver
Description : megasas2i
State : Stopped

Name : megasr
Path : C:\Windows\system32\drivers\megasr.sys
Service Type : Kernel Driver
Description : megasr
State : Stopped

Name : mlx4_bus
Path : C:\Windows\system32\drivers\mlx4_bus.sys
Service Type : Kernel Driver
Description : Mellanox ConnectX Bus Enumerator
State : Stopped

Name : MMCSS
Path : C:\Windows\system32\drivers\mmcss.sys
Service Type : Kernel Driver
Description : Multimedia Class Scheduler
State : Stopped

Name : Modem
Path : C:\Windows\system32\drivers\modem.sys
Service Type : Kernel Driver
Description : Modem
State : Stopped

Name : monitor
Path : C:\Windows\system32\drivers\monitor.sys
Service Type : Kernel Driver
Description : Microsoft Monitor Class Function Driver Service
State : Running

Name : mouclass
Path : C:\Windows\system32\drivers\mouclass.sys
Service Type : Kernel Driver
Description : Mouse Class Driver
State : Running

Name : mouhid
Path : C:\Windows\system32\drivers\mouhid.sys
Service Type : Kernel Driver
Description : Mouse HID Driver
State : Stopped

Name : mountmgr
Path : C:\Windows\system32\drivers\mountmgr.sys
Service Type : Kernel Driver
Description : Mount Point Manager
State : Running

Name : mpsdrv
Path : C:\Windows\system32\drivers\mpsdrv.sys
Service Type : Kernel Driver
Description : Windows Firewall Authorization Driver
State : Running

Name : mrxsmb
Path : C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Type : File System Driver
Description : SMB MiniRedirector Wrapper and Engine
State : Running

Name : mrxsmb10
Path : C:\Windows\system32\DRIVERS\mrxsmb10.sys
Service Type : File System Driver
Description : SMB 1.x MiniRedirector
State : Running

Name : mrxsmb20
Path : C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Type : File System Driver
Description : SMB 2.0 MiniRedirector
State : Running

Name : MsBridge
Path : C:\Windows\system32\drivers\bridge.sys
Service Type : Kernel Driver
Description : Microsoft MAC Bridge
State : Stopped

Name : Msfs
Path : C:\Windows\system32\drivers\Msfs.sys
Service Type : File System Driver
Description : Msfs
State : Running

Name : msgpiowin32
Path : C:\Windows\system32\drivers\msgpiowin32.sys
Service Type : Kernel Driver
Description : Common Driver for Buttons, DockMode and Laptop/Slate Indicator
State : Stopped

Name : mshidkmdf
Path : C:\Windows\system32\drivers\mshidkmdf.sys
Service Type : Kernel Driver
Description : mshidkmdf
State : Stopped

Name : mshidumdf
Path : C:\Windows\system32\drivers\mshidumdf.sys
Service Type : Kernel Driver
Description : Pass-through HID to UMDF Driver
State : Stopped

Name : msisadrv
Path : C:\Windows\system32\drivers\msisadrv.sys
Service Type : Kernel Driver
Description : msisadrv
State : Running

Name : MSKSSRV
Path : C:\Windows\system32\DRIVERS\MSKSSRV.sys
Service Type : Kernel Driver
Description : Microsoft Streaming Service Proxy
State : Stopped

Name : MsLbfoProvider
Path : C:\Windows\system32\drivers\MsLbfoProvider.sys
Service Type : Kernel Driver
Description : Microsoft Load Balancing/Failover Provider
State : Stopped

Name : MsLldp
Path : C:\Windows\system32\drivers\mslldp.sys
Service Type : Kernel Driver
Description : Microsoft Link-Layer Discovery Protocol
State : Running

Name : MsRPC
Path : C:\Windows\system32\drivers\MsRPC.sys
Service Type : Kernel Driver
Description : MsRPC
State : Stopped

Name : mssmbios
Path : C:\Windows\system32\drivers\mssmbios.sys
Service Type : Kernel Driver
Description : Microsoft System Management BIOS Driver
State : Running

Name : MTConfig
Path : C:\Windows\system32\drivers\MTConfig.sys
Service Type : Kernel Driver
Description : Microsoft Input Configuration Driver
State : Stopped

Name : Mup
Path : C:\Windows\system32\Drivers\mup.sys
Service Type : File System Driver
Description : Mup
State : Running

Name : mvumis
Path : C:\Windows\system32\drivers\mvumis.sys
Service Type : Kernel Driver
Description : mvumis
State : Stopped

Name : ndfltr
Path : C:\Windows\system32\drivers\ndfltr.sys
Service Type : Kernel Driver
Description : NetworkDirect Service
State : Stopped

Name : NDIS
Path : C:\Windows\system32\drivers\ndis.sys
Service Type : Kernel Driver
Description : NDIS System Driver
State : Running

Name : NdisCap
Path : C:\Windows\system32\drivers\ndiscap.sys
Service Type : Kernel Driver
Description : Microsoft NDIS Capture
State : Stopped

Name : NdisImPlatform
Path : C:\Windows\system32\drivers\NdisImPlatform.sys
Service Type : Kernel Driver
Description : Microsoft Network Adapter Multiplexor Protocol
State : Stopped

Name : NdisTapi
Path : C:\Windows\system32\DRIVERS\ndistapi.sys
Service Type : Kernel Driver
Description : Remote Access NDIS TAPI Driver
State : Stopped

Name : Ndisuio
Path : C:\Windows\system32\drivers\ndisuio.sys
Service Type : Kernel Driver
Description : NDIS Usermode I/O Protocol
State : Stopped

Name : NdisVirtualBus
Path : C:\Windows\system32\drivers\NdisVirtualBus.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Network Adapter Enumerator
State : Running

Name : NdisWan
Path : C:\Windows\system32\drivers\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access NDIS WAN Driver
State : Stopped

Name : ndiswanlegacy
Path : C:\Windows\system32\DRIVERS\ndiswan.sys
Service Type : Kernel Driver
Description : Remote Access LEGACY NDIS WAN Driver
State : Stopped

Name : ndproxy
Path : C:\Windows\system32\DRIVERS\NDProxy.sys
Service Type : Kernel Driver
Description : @%SystemRoot%\system32\drivers\todo.sys,-101;NDIS Proxy
State : Stopped

Name : NetBIOS
Path : C:\Windows\system32\drivers\netbios.sys
Service Type : File System Driver
Description : NetBIOS Interface
State : Running

Name : NetBT
Path : C:\Windows\system32\DRIVERS\netbt.sys
Service Type : Kernel Driver
Description : NetBT
State : Running

Name : netvsc
Path : C:\Windows\system32\drivers\netvsc.sys
Service Type : Kernel Driver
Description : netvsc
State : Stopped

Name : Npfs
Path : C:\Windows\system32\drivers\Npfs.sys
Service Type : File System Driver
Description : Npfs
State : Running

Name : npsvctrig
Path : C:\Windows\system32\drivers\npsvctrig.sys
Service Type : Kernel Driver
Description : Named pipe service trigger provider
State : Running

Name : nsiproxy
Path : C:\Windows\system32\drivers\nsiproxy.sys
Service Type : Kernel Driver
Description : NSI Proxy Service Driver
State : Running

Name : NTFS
Path : C:\Windows\system32\drivers\NTFS.sys
Service Type : File System Driver
Description : NTFS
State : Running

Name : Null
Path : C:\Windows\system32\drivers\Null.sys
Service Type : Kernel Driver
Description : Null
State : Running

Name : nvraid
Path : C:\Windows\system32\drivers\nvraid.sys
Service Type : Kernel Driver
Description : nvraid
State : Stopped

Name : nvstor
Path : C:\Windows\system32\drivers\nvstor.sys
Service Type : Kernel Driver
Description : nvstor
State : Stopped

Name : Parport
Path : C:\Windows\system32\drivers\parport.sys
Service Type : Kernel Driver
Description : Parallel port driver
State : Stopped

Name : partmgr
Path : C:\Windows\system32\drivers\partmgr.sys
Service Type : Kernel Driver
Description : Partition driver
State : Running

Name : pci
Path : C:\Windows\system32\drivers\pci.sys
Service Type : Kernel Driver
Description : PCI Bus Driver
State : Running

Name : pciide
Path : C:\Windows\system32\drivers\pciide.sys
Service Type : Kernel Driver
Description : pciide
State : Running

Name : pcmcia
Path : C:\Windows\system32\drivers\pcmcia.sys
Service Type : Kernel Driver
Description : pcmcia
State : Stopped

Name : pcw
Path : C:\Windows\system32\drivers\pcw.sys
Service Type : Kernel Driver
Description : Performance Counters for Windows Driver
State : Running

Name : pdc
Path : C:\Windows\system32\drivers\pdc.sys
Service Type : Kernel Driver
Description : pdc
State : Running

Name : PEAUTH
Path : C:\Windows\system32\drivers\peauth.sys
Service Type : Kernel Driver
Description : PEAUTH
State : Running

Name : percsas2i
Path : C:\Windows\system32\drivers\percsas2i.sys
Service Type : Kernel Driver
Description : percsas2i
State : Stopped

Name : percsas3i
Path : C:\Windows\system32\drivers\percsas3i.sys
Service Type : Kernel Driver
Description : percsas3i
State : Stopped

Name : PptpMiniport
Path : C:\Windows\system32\drivers\raspptp.sys
Service Type : Kernel Driver
Description : WAN Miniport (PPTP)
State : Stopped

Name : Processor
Path : C:\Windows\system32\drivers\processr.sys
Service Type : Kernel Driver
Description : Processor Driver
State : Stopped

Name : Psched
Path : C:\Windows\system32\drivers\pacer.sys
Service Type : Kernel Driver
Description : QoS Packet Scheduler
State : Running

Name : ql2300i
Path : C:\Windows\system32\drivers\ql2300i.sys
Service Type : Kernel Driver
Description : QLogic Fibre Channel STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : ql40xx2i
Path : C:\Windows\system32\drivers\ql40xx2i.sys
Service Type : Kernel Driver
Description : QLogic iSCSI Miniport Inbox Driver
State : Stopped

Name : qlfcoei
Path : C:\Windows\system32\drivers\qlfcoei.sys
Service Type : Kernel Driver
Description : QLogic [FCoE] STOR Miniport Inbox Driver (wx64)
State : Stopped

Name : QWAVEdrv
Path : C:\Windows\system32\drivers\qwavedrv.sys
Service Type : Kernel Driver
Description : QWAVE driver
State : Stopped

Name : RasAcd
Path : C:\Windows\system32\DRIVERS\rasacd.sys
Service Type : Kernel Driver
Description : Remote Access Auto Connection Driver
State : Stopped

Name : RasAgileVpn
Path : C:\Windows\system32\drivers\AgileVpn.sys
Service Type : Kernel Driver
Description : WAN Miniport (IKEv2)
State : Stopped

Name : RasGre
Path : C:\Windows\system32\drivers\rasgre.sys
Service Type : Kernel Driver
Description : WAN Miniport (GRE)
State : Stopped

Name : Rasl2tp
Path : C:\Windows\system32\drivers\rasl2tp.sys
Service Type : Kernel Driver
Description : WAN Miniport (L2TP)
State : Stopped

Name : RasPppoe
Path : C:\Windows\system32\drivers\raspppoe.sys
Service Type : Kernel Driver
Description : Remote Access PPPOE Driver
State : Stopped

Name : RasSstp
Path : C:\Windows\system32\drivers\rassstp.sys
Service Type : Kernel Driver
Description : WAN Miniport (SSTP)
State : Stopped

Name : rdbss
Path : C:\Windows\system32\DRIVERS\rdbss.sys
Service Type : File System Driver
Description : Redirected Buffering Sub System
State : Running

Name : rdpbus
Path : C:\Windows\system32\drivers\rdpbus.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Bus Driver
State : Running

Name : RDPDR
Path : C:\Windows\system32\drivers\rdpdr.sys
Service Type : Kernel Driver
Description : Remote Desktop Device Redirector Driver
State : Running

Name : RdpVideoMiniport
Path : C:\Windows\system32\drivers\rdpvideominiport.sys
Service Type : Kernel Driver
Description : Remote Desktop Video Miniport Driver
State : Running

Name : ReFS
Path : C:\Windows\system32\drivers\ReFS.sys
Service Type : File System Driver
Description : ReFS
State : Stopped

Name : ReFSv1
Path : C:\Windows\system32\drivers\ReFSv1.sys
Service Type : File System Driver
Description : ReFSv1
State : Stopped

Name : RsFx0411
Path : C:\Windows\system32\DRIVERS\RsFx0411.sys
Service Type : File System Driver
Description : RsFx0411 Driver
State : Stopped

Name : RsFx0600
Path : C:\Windows\system32\DRIVERS\RsFx0600.sys
Service Type : File System Driver
Description : RsFx0600 Driver
State : Stopped

Name : rspndr
Path : C:\Windows\system32\drivers\rspndr.sys
Service Type : Kernel Driver
Description : Link-Layer Topology Discovery Responder
State : Running

Name : s3cap
Path : C:\Windows\system32\drivers\vms3cap.sys
Service Type : Kernel Driver
Description : s3cap
State : Stopped

Name : sacdrv
Path : C:\Windows\system32\DRIVERS\sacdrv.sys
Service Type : Kernel Driver
Description : sacdrv
State : Stopped

Name : sbp2port
Path : C:\Windows\system32\drivers\sbp2port.sys
Service Type : Kernel Driver
Description : SBP-2 Transport/Protocol Bus Driver
State : Stopped

Name : scfilter
Path : C:\Windows\system32\DRIVERS\scfilter.sys
Service Type : Kernel Driver
Description : Smart card PnP Class Filter Driver
State : Stopped

Name : scmbus
Path : C:\Windows\system32\drivers\scmbus.sys
Service Type : Kernel Driver
Description : Microsoft Storage Class Memory Bus Driver
State : Stopped

Name : scmdisk0101
Path : C:\Windows\system32\drivers\scmdisk0101.sys
Service Type : Kernel Driver
Description : Microsoft NVDIMM-N disk driver
State : Stopped

Name : sdbus
Path : C:\Windows\system32\drivers\sdbus.sys
Service Type : Kernel Driver
Description : sdbus
State : Stopped

Name : sdstor
Path : C:\Windows\system32\drivers\sdstor.sys
Service Type : Kernel Driver
Description : SD Storage Port Driver
State : Stopped

Name : SerCx
Path : C:\Windows\system32\drivers\SerCx.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : SerCx2
Path : C:\Windows\system32\drivers\SerCx2.sys
Service Type : Kernel Driver
Description : Serial UART Support Library
State : Stopped

Name : Serenum
Path : C:\Windows\system32\drivers\serenum.sys
Service Type : Kernel Driver
Description : Serenum Filter Driver
State : Running

Name : Serial
Path : C:\Windows\system32\drivers\serial.sys
Service Type : Kernel Driver
Description : Serial port driver
State : Running

Name : sermouse
Path : C:\Windows\system32\drivers\sermouse.sys
Service Type : Kernel Driver
Description : Serial Mouse Driver
State : Stopped

Name : sfloppy
Path : C:\Windows\system32\drivers\sfloppy.sys
Service Type : Kernel Driver
Description : High-Capacity Floppy Disk Drive
State : Stopped

Name : SiSRaid2
Path : C:\Windows\system32\drivers\SiSRaid2.sys
Service Type : Kernel Driver
Description : SiSRaid2
State : Stopped

Name : SiSRaid4
Path : C:\Windows\system32\drivers\sisraid4.sys
Service Type : Kernel Driver
Description : SiSRaid4
State : Stopped

Name : smbdirect
Path : C:\Windows\system32\DRIVERS\smbdirect.sys
Service Type : File System Driver
Description : smbdirect
State : Stopped

Name : spaceport
Path : C:\Windows\system32\drivers\spaceport.sys
Service Type : Kernel Driver
Description : Storage Spaces Driver
State : Running

Name : SpbCx
Path : C:\Windows\system32\drivers\SpbCx.sys
Service Type : Kernel Driver
Description : Simple Peripheral Bus Support Library
State : Stopped

Name : srv
Path : C:\Windows\system32\DRIVERS\srv.sys
Service Type : File System Driver
Description : Server SMB 1.xxx Driver
State : Running

Name : srv2
Path : C:\Windows\system32\DRIVERS\srv2.sys
Service Type : File System Driver
Description : Server SMB 2.xxx Driver
State : Running

Name : srvnet
Path : C:\Windows\system32\DRIVERS\srvnet.sys
Service Type : File System Driver
Description : srvnet
State : Running

Name : stexstor
Path : C:\Windows\system32\drivers\stexstor.sys
Service Type : Kernel Driver
Description : stexstor
State : Stopped

Name : storahci
Path : C:\Windows\system32\drivers\storahci.sys
Service Type : Kernel Driver
Description : Microsoft Standard SATA AHCI Driver
State : Stopped

Name : storflt
Path : C:\Windows\system32\drivers\vmstorfl.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Storage Accelerator
State : Stopped

Name : stornvme
Path : C:\Windows\system32\drivers\stornvme.sys
Service Type : Kernel Driver
Description : Microsoft Standard NVM Express Driver
State : Stopped

Name : storqosflt
Path : C:\Windows\system32\drivers\storqosflt.sys
Service Type : File System Driver
Description : Storage QoS Filter Driver
State : Running

Name : storufs
Path : C:\Windows\system32\drivers\storufs.sys
Service Type : Kernel Driver
Description : Microsoft Universal Flash Storage (UFS) Driver
State : Stopped

Name : storvsc
Path : C:\Windows\system32\drivers\storvsc.sys
Service Type : Kernel Driver
Description : storvsc
State : Stopped

Name : swenum
Path : C:\Windows\system32\drivers\swenum.sys
Service Type : Kernel Driver
Description : Software Bus Driver
State : Running

Name : Synth3dVsc
Path : C:\Windows\system32\drivers\Synth3dVsc.sys
Service Type : Kernel Driver
Description : Synth3dVsc
State : Stopped

Name : Tcpip
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : TCP/IP Protocol Driver
State : Running

Name : Tcpip6
Path : C:\Windows\system32\drivers\tcpip.sys
Service Type : Kernel Driver
Description : @todo.dll,-100;Microsoft IPv6 Protocol Driver
State : Stopped

Name : tcpipreg
Path : C:\Windows\system32\drivers\tcpipreg.sys
Service Type : Kernel Driver
Description : TCP/IP Registry Compatibility
State : Running

Name : tdx
Path : C:\Windows\system32\DRIVERS\tdx.sys
Service Type : Kernel Driver
Description : NetIO Legacy TDI Support Driver
State : Running

Name : terminpt
Path : C:\Windows\system32\drivers\terminpt.sys
Service Type : Kernel Driver
Description : Microsoft Remote Desktop Input Driver
State : Running

Name : TPM
Path : C:\Windows\system32\drivers\tpm.sys
Service Type : Kernel Driver
Description : TPM
State : Stopped

Name : TsUsbFlt
Path : C:\Windows\system32\drivers\tsusbflt.sys
Service Type : Kernel Driver
Description : TsUsbFlt
State : Stopped

Name : TsUsbGD
Path : C:\Windows\system32\drivers\TsUsbGD.sys
Service Type : Kernel Driver
Description : Remote Desktop Generic USB Device
State : Stopped

Name : tsusbhub
Path : C:\Windows\system32\drivers\tsusbhub.sys
Service Type : Kernel Driver
Description : Remote Desktop USB Hub
State : Stopped

Name : tunnel
Path : C:\Windows\system32\drivers\tunnel.sys
Service Type : Kernel Driver
Description : Microsoft Tunnel Miniport Adapter Driver
State : Running

Name : UASPStor
Path : C:\Windows\system32\drivers\uaspstor.sys
Service Type : Kernel Driver
Description : USB Attached SCSI (UAS) Driver
State : Running

Name : UcmCx0101
Path : C:\Windows\system32\Drivers\UcmCx.sys
Service Type : Kernel Driver
Description : USB Connector Manager KMDF Class Extension
State : Stopped

Name : UcmTcpciCx0101
Path : C:\Windows\system32\Drivers\UcmTcpciCx.sys
Service Type : Kernel Driver
Description : UCM-TCPCI KMDF Class Extension
State : Stopped

Name : UcmUcsi
Path : C:\Windows\system32\drivers\UcmUcsi.sys
Service Type : Kernel Driver
Description : USB Connector Manager UCSI Client
State : Stopped

Name : Ucx01000
Path : C:\Windows\system32\drivers\ucx01000.sys
Service Type : Kernel Driver
Description : USB Host Support Library
State : Stopped

Name : UdeCx
Path : C:\Windows\system32\drivers\udecx.sys
Service Type : Kernel Driver
Description : USB Device Emulation Support Library
State : Stopped

Name : udfs
Path : C:\Windows\system32\DRIVERS\udfs.sys
Service Type : File System Driver
Description : udfs
State : Stopped

Name : UEFI
Path : C:\Windows\system32\drivers\UEFI.sys
Service Type : Kernel Driver
Description : Microsoft UEFI Driver
State : Stopped

Name : UevAgentDriver
Path : C:\Windows\system32\drivers\UevAgentDriver.sys
Service Type : File System Driver
Description : UevAgentDriver
State : Stopped

Name : Ufx01000
Path : C:\Windows\system32\drivers\ufx01000.sys
Service Type : Kernel Driver
Description : USB Function Class Extension
State : Stopped

Name : UfxChipidea
Path : C:\Windows\system32\drivers\UfxChipidea.sys
Service Type : Kernel Driver
Description : USB Chipidea Controller
State : Stopped

Name : ufxsynopsys
Path : C:\Windows\system32\drivers\ufxsynopsys.sys
Service Type : Kernel Driver
Description : USB Synopsys Controller
State : Stopped

Name : umbus
Path : C:\Windows\system32\drivers\umbus.sys
Service Type : Kernel Driver
Description : UMBus Enumerator Driver
State : Running

Name : UmPass
Path : C:\Windows\system32\drivers\umpass.sys
Service Type : Kernel Driver
Description : Microsoft UMPass Driver
State : Stopped

Name : UrsChipidea
Path : C:\Windows\system32\drivers\urschipidea.sys
Service Type : Kernel Driver
Description : Chipidea USB Role-Switch Driver
State : Stopped

Name : UrsCx01000
Path : C:\Windows\system32\drivers\urscx01000.sys
Service Type : Kernel Driver
Description : USB Role-Switch Support Library
State : Stopped

Name : UrsSynopsys
Path : C:\Windows\system32\drivers\urssynopsys.sys
Service Type : Kernel Driver
Description : Synopsys USB Role-Switch Driver
State : Stopped

Name : usbccgp
Path : C:\Windows\system32\drivers\usbccgp.sys
Service Type : Kernel Driver
Description : Microsoft USB Generic Parent Driver
State : Stopped

Name : usbehci
Path : C:\Windows\system32\drivers\usbehci.sys
Service Type : Kernel Driver
Description : Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
State : Running

Name : usbhub
Path : C:\Windows\system32\drivers\usbhub.sys
Service Type : Kernel Driver
Description : Microsoft USB Standard Hub Driver
State : Running

Name : USBHUB3
Path : C:\Windows\system32\drivers\UsbHub3.sys
Service Type : Kernel Driver
Description : SuperSpeed Hub
State : Stopped

Name : usbohci
Path : C:\Windows\system32\drivers\usbohci.sys
Service Type : Kernel Driver
Description : Microsoft USB Open Host Controller Miniport Driver
State : Stopped

Name : usbprint
Path : C:\Windows\system32\drivers\usbprint.sys
Service Type : Kernel Driver
Description : Microsoft USB PRINTER Class
State : Stopped

Name : usbser
Path : C:\Windows\system32\drivers\usbser.sys
Service Type : Kernel Driver
Description : Microsoft USB Serial Driver
State : Stopped

Name : USBSTOR
Path : C:\Windows\system32\drivers\USBSTOR.SYS
Service Type : Kernel Driver
Description : USB Mass Storage Driver
State : Stopped

Name : usbuhci
Path : C:\Windows\system32\drivers\usbuhci.sys
Service Type : Kernel Driver
Description : Microsoft USB Universal Host Controller Miniport Driver
State : Running

Name : USBXHCI
Path : C:\Windows\system32\drivers\USBXHCI.SYS
Service Type : Kernel Driver
Description : USB xHCI Compliant Host Controller
State : Stopped

Name : vdrvroot
Path : C:\Windows\system32\drivers\vdrvroot.sys
Service Type : Kernel Driver
Description : Microsoft Virtual Drive Enumerator
State : Running

Name : VerifierExt
Path : C:\Windows\system32\drivers\VerifierExt.sys
Service Type : Kernel Driver
Description : VerifierExt
State : Stopped

Name : vhdmp
Path : C:\Windows\system32\drivers\vhdmp.sys
Service Type : Kernel Driver
Description : vhdmp
State : Stopped

Name : vhf
Path : C:\Windows\system32\drivers\vhf.sys
Service Type : Kernel Driver
Description : Virtual HID Framework (VHF) Driver
State : Stopped

Name : vmbus
Path : C:\Windows\system32\drivers\vmbus.sys
Service Type : Kernel Driver
Description : Virtual Machine Bus
State : Stopped

Name : VMBusHID
Path : C:\Windows\system32\drivers\VMBusHID.sys
Service Type : Kernel Driver
Description : VMBusHID
State : Stopped

Name : vmgid
Path : C:\Windows\system32\drivers\vmgid.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Guest Infrastructure Driver
State : Stopped

Name : volmgr
Path : C:\Windows\system32\drivers\volmgr.sys
Service Type : Kernel Driver
Description : Volume Manager Driver
State : Running

Name : volmgrx
Path : C:\Windows\system32\drivers\volmgrx.sys
Service Type : Kernel Driver
Description : Dynamic Volume Manager
State : Running

Name : volsnap
Path : C:\Windows\system32\drivers\volsnap.sys
Service Type : Kernel Driver
Description : Volume Shadow Copy driver
State : Running

Name : volume
Path : C:\Windows\system32\drivers\volume.sys
Service Type : Kernel Driver
Description : Volume driver
State : Running

Name : vpci
Path : C:\Windows\system32\drivers\vpci.sys
Service Type : Kernel Driver
Description : Microsoft Hyper-V Virtual PCI Bus
State : Stopped

Name : vsmraid
Path : C:\Windows\system32\drivers\vsmraid.sys
Service Type : Kernel Driver
Description : vsmraid
State : Stopped

Name : VSTXRAID
Path : C:\Windows\system32\drivers\vstxraid.sys
Service Type : Kernel Driver
Description : VIA StorX Storage RAID Controller Windows Driver
State : Stopped

Name : WacomPen
Path : C:\Windows\system32\drivers\wacompen.sys
Service Type : Kernel Driver
Description : Wacom Serial Pen HID Driver
State : Stopped

Name : wanarp
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IP ARP Driver
State : Stopped

Name : wanarpv6
Path : C:\Windows\system32\DRIVERS\wanarp.sys
Service Type : Kernel Driver
Description : Remote Access IPv6 ARP Driver
State : Stopped

Name : wcifs
Path : C:\Windows\system32\drivers\wcifs.sys
Service Type : File System Driver
Description : Windows Container Isolation
State : Running

Name : wcnfs
Path : C:\Windows\system32\drivers\wcnfs.sys
Service Type : File System Driver
Description : Windows Container Name Virtualization
State : Stopped

Name : Wdf01000
Path : C:\Windows\system32\drivers\Wdf01000.sys
Service Type : Kernel Driver
Description : Kernel Mode Driver Frameworks service
State : Running

Name : WFPLWFS
Path : C:\Windows\system32\drivers\wfplwfs.sys
Service Type : Kernel Driver
Description : Microsoft Windows Filtering Platform
State : Running

Name : WIMMount
Path : C:\Windows\system32\drivers\wimmount.sys
Service Type : File System Driver
Description : WIMMount
State : Stopped

Name : WindowsTrustedRT
Path : C:\Windows\system32\drivers\WindowsTrustedRT.sys
Service Type : Kernel Driver
Description : Windows Trusted Execution Environment Class Extension
State : Running

Name : WindowsTrustedRTProxy
Path : C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys
Service Type : Kernel Driver
Description : Microsoft Windows Trusted Runtime Secure Service
State : Running

Name : WinMad
Path : C:\Windows\system32\drivers\winmad.sys
Service Type : Kernel Driver
Description : WinMad Service
State : Stopped

Name : WinNat
Path : C:\Windows\system32\drivers\winnat.sys
Service Type : Kernel Driver
Description : Windows NAT Driver
State : Stopped

Name : WINUSB
Path : C:\Windows\system32\drivers\WinUSB.SYS
Service Type : Kernel Driver
Description : WinUsb Driver
State : Stopped

Name : WinVerbs
Path : C:\Windows\system32\drivers\winverbs.sys
Service Type : Kernel Driver
Description : WinVerbs Service
State : Stopped

Name : WmiAcpi
Path : C:\Windows\system32\drivers\wmiacpi.sys
Service Type : Kernel Driver
Description : Microsoft Windows Management Interface for ACPI
State : Stopped

Name : Wof
Path : C:\Windows\system32\drivers\Wof.sys
Service Type : File System Driver
Description : Windows Overlay File System Filter Driver
State : Running

Name : WpdUpFltr
Path : C:\Windows\system32\drivers\WpdUpFltr.sys
Service Type : Kernel Driver
Description : WPD Upper Class Filter Driver
State : Stopped

Name : ws2ifsl
Path : C:\Windows\system32\drivers\ws2ifsl.sys
Service Type : Kernel Driver
Description : Winsock IFS Driver
State : Stopped

Name : WudfPf
Path : C:\Windows\system32\drivers\WudfPf.sys
Service Type : Kernel Driver
Description : User Mode Driver Frameworks Platform Driver
State : Running

Name : WUDFRd
Path : C:\Windows\system32\drivers\WUDFRd.sys
Service Type : Kernel Driver
Description : WUDFRd
State : Stopped

Name : WUDFWpdFs
Path : C:\Windows\system32\DRIVERS\WUDFRd.sys
Service Type : Kernel Driver
Description : WUDFWpdFs
State : Stopped

Name : xboxgip
Path : C:\Windows\system32\drivers\xboxgip.sys
Service Type : Kernel Driver
Description : Xbox Game Input Protocol Driver
State : Stopped

Name : xinputhid
Path : C:\Windows\system32\drivers\xinputhid.sys
Service Type : Kernel Driver
Description : XINPUT HID Filter Driver
State : Stopped
92438 - WordPad History
-
Synopsis
Nessus was able to gather WordPad opened file history on the remote host.
Description
Nessus was able to generate a report of files opened in WordPad on the remote host.
See Also
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2016/07/19, Modified: 2018/05/23
Plugin Output

tcp/0

D:\XTPL\APPS\JBCastLite\DB_ADDRESS.xml
D:\XTPL\Pledge Tomcat\apache-tomcat-9.0.104\conf\server.xml
D:\XTPL\Pledge Tomcat\apache-tomcat-9.0.104\webapps\transaction\WEB-INF\web.xml
D:\XTPL\Pledge Tomcat\apache-tomcat-9.0.104\webapps\Pledge\WEB-INF\web.xml
D:\XTPL\Tomcat\conf\server.xml

WordPad report attached.
Compliance 'FAILED'
Compliance 'SKIPPED'
Compliance 'PASSED'
Compliance 'INFO', 'WARNING', 'ERROR'
Remediations
Suggested Remediations
Taking the following actions across 10 hosts would resolve 28% of the vulnerabilities on the network.
Action to take Vulns Hosts
KB4577015: Windows 10 Version 1607 and Windows Server 2016 September 2020 Security Update: Apply Cumulative Update KB4577015. 1130 1
Security Updates for Microsoft SQL Server (November 2025): Microsoft has released security updates for Microsoft SQL Server. 714 7
Security Updates for Microsoft Office Products (December 2025): Microsoft has released the following updates to address these issues: - KB5002812 - KB5002818 - KB5002819 545 1
Security Updates for Microsoft Office Products (April 2021): Microsoft has released the following security updates to address this issue: -KB2553491 -KB2589361 -KB3178639 -KB3178643 -KB4504738 -KB4504722 -KB4504726 -KB4504724 -KB4504739 -KB4504727 322 1
Install KB5071544 259 7
Oracle Database Multiple Vulnerabilities (April 2012 CPU): Apply the appropriate patch according to the April 2012 Oracle Critical Patch Update advisory. 174 1
Security Updates for Microsoft .NET Framework (January 2025): Microsoft has released security updates for Microsoft .NET Framework. 168 6
Security Updates for Microsoft SQL Server OLE DB Driver (July 2024): Microsoft has released security updates for the Microsoft SQL OLE DB Driver. 168 6
Oracle Java SE Multiple Vulnerabilities (October 2025 CPU): Apply the appropriate patch according to the October 2025 Oracle Critical Patch Update advisory. 148 2
Mozilla Firefox < 146.0.1: Upgrade to Mozilla Firefox version 146.0.1 or later. 126 1
Install KB5071543 118 2
Security Update for Microsoft .NET Core (October 2025): Update .NET Core, remove vulnerable packages and refer to vendor advisory. 102 2
Security Updates for Microsoft Excel Products (April 2021): Microsoft has released the following security updates to address this issue: -KB3017810 -KB4504721 -KB4504735 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 96 1
Security Updates for Microsoft Word Products (December 2025): Microsoft has released KB5002806 to address this issue. 81 1
RARLAB WinRAR < 7.13 Directory Traversal (CVE-2025-8088): Upgrade to RARLAB WinRAR version 7.13 or later. 63 9
Security Updates for Microsoft Office Products (March 2021): Microsoft has released the following security updates to address this issue: -KB4493228 -KB4493203 -KB4504703 -KB4493225 -KB4493200 -KB4493214 59 1
Security Updates for Outlook (July 2025): Microsoft has released KB5002747 to address this issue. 48 1
Install KB5002406 45 1
Install KB4484243 43 1
Security Updates for Microsoft Word Products (April 2021): Microsoft has released the following security updates to address this issue: -KB4493208 -KB4493218 -KB4493198 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 41 1
7-Zip < 25.01: Upgrade to 7-Zip version 25.01 or later. 33 3
Security Updates for Microsoft .NET Framework (October 2020): Microsoft has released security updates for Microsoft .NET Framework. 30 1
Microsoft ASP.NET Core Security Feature Bypass (October 2025): Update .NET Core to version 8.0.21, 9.0.10, 10.0.0-rc.2.25502.107 or later. 30 2
Install KB4484217 29 1
Security Updates for Outlook (April 2021): Microsoft has released the following security updates to address this issue: -KB4504712 -KB4504733 -KB4493185 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 26 1
Install KB5002253 25 1
Install KB5002427 23 1
Node.js Multiple Vulnerabilities (November 2018 Security Releases): Upgrade Node.js to 6.15 / 8.14.0 / 10.14.0 / 11.3.0 or later. 20 1
Install KB5002820 20 1
Apache Tomcat 9.0.0.M1 < 9.0.110: Upgrade to Apache Tomcat version 9.0.110 or later. 20 1
Install KB4493185 19 1
Install KB4504739 18 1
MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080): Microsoft has released a set of patches for Excel 2007, Excel 2010, Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and Office Compatibility Pack. 18 1
Notepad++ < 8.8.2 Privilege Escalation (CVE-2025-49144): Upgrade to Notepad++ 8.8.2 or later. 18 3
Security Updates for Microsoft PowerPoint Products (October 2025): Microsoft has released KB5002790 to address this issue. 15 1
VMware Tools 11.x < 12.5.4 / 13.x < 13.0.5 Multiple Vulnerabilities (VMSA-2025-0015): Upgrade to VMware Tools version 12.5.4, 13.0.5 or later. 15 5
Install KB5002790 14 1
Security Updates for Outlook (January 2019): Microsoft has released the following security updates to address this issue: -KB4461595 -KB4461601 -KB4461623 For Office 365, Office 2016 C2R, or Office 2019, ensure automatic updates are enabled or open any office app and manually perform an update. 14 1
Install KB5044280 12 1
MS17-013: Security Update for Microsoft Graphics Component (4013075): Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, 2008 R2, 2012, 8.1, RT 8.1, 2012 R2, 10, and 2016. Additionally, Microsoft has released a set of patches for Office 2007, Office 2010, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2010 Attendee, Lync 2013, Lync Basic 2013, Live Meeting 2007 Console, and Silverlight 5. 12 1
Install KB5002806 12 1
Security Updates for Microsoft .NET Framework (October 2024): Microsoft has released security updates for Microsoft .NET Framework. 11 1
Install KB4504707 11 1
Install KB4493218 11 1
Install KB4461625 11 1
Install KB4504702 9 1
Security Updates for Microsoft PowerPoint Products (March 2021): Microsoft has released the following security updates to address this issue: -KB4493227 -KB4504702 -KB4493224 9 1
MS09-035: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706): Microsoft has released a set of patches for Visual Studio .NET 2003, Visual Studio 2005 and 2008, as well as Visual C++ 2005 and 2008. 9 3
Install KB3178687 8 1
Install KB3115197 8 1
Install KB5002683 8 1
Install KB3178702 8 1
Security Updates for Microsoft Excel Products (December 2025): Microsoft has released KB5002820 to address this issue. 6 1
Security Updates for Microsoft Publisher Products (September 2024): Microsoft has released KB5002566 to address this issue. 6 1
Visual Studio Tools for Applications Elevation of Privilege (CVE-2025-29803): Upgrade to VSTA 16.0.35907.0, 17.0.35906.0 or later. 6 6
Install KB4032216 5 1
Oracle MySQL Connectors (October 2024 CPU): Apply the appropriate patch according to the October 2024 Oracle Critical Patch Update advisory. 5 1
Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104): Upgrade to Apache Log4j version 2.16.0 or later since 1.x is end of life. Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate versions / patches have known high severity vulnerabilities and the vendor is updating their advisories often as new research and knowledge about the impact of Log4j is discovered. Refer to https://logging.apache.org/log4j/2.x/security.html for the latest versions. 5 5
Install KB5002426 4 1
MS13-094: Vulnerability in Microsoft Outlook Could Allow Information Disclosure (2894514): Microsoft has released a set of patches for Office 2007, 2010, 2013 and 2013 RT. 4 2
Install MS18-01 3 1
Install KB3203467 3 1
Security Updates for Microsoft Publisher Products (April 2020): Microsoft has released the following security updates to address this issue: -KB3162033 -KB4011097 -KB4032216 3 1
Install MS18-01 3 1
Install KB5002221 3 1
JQuery 1.2 < 3.5.0 Multiple XSS: Upgrade to JQuery version 3.5.0 or later. 2 1
VMware Tools 10.x / 11.x / 12.x < 12.1.5 DoS (VMSA-2022-0029): Upgrade to VMware Tools version 12.1.5 or later. 2 1
Install KB4484455 2 1
Install KB3213626 2 1
Install KB3115246 2 1
Install KB3054834 2 1
Install KB2881029 2 1
Install KB5002566 2 1
Install KB3213551 2 1
Install KB3191932 2 1
Curl Use-After-Free < 7.87 (CVE-2022-43552): Upgrade Curl to version 7.87.0 or later 2 2
MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019): Microsoft has released a set of patches for Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1. 2 2
Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039): Upgrade Curl to version 8.3.0 or later 2 2
Security Update for Microsoft Visual Studio Code Python Extension (July 2025): Update the Microsoft Visual Studio Code Python Extension to version 2025.8.1 or later. 1 1
Install KB4504738 1 1
Install KB3213636 1 1
Install KB3191908 1 1
Install KB3115248 1 1
Install KB3114885 1 1
Install KB3114565 1 1
Install KB3114400 1 1
Install KB2965313 1 1
Install KB2920812 1 1
Install KB2889841 1 1
Install KB2579115 1 1
MS11-049: Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893): Microsoft has released a set of patches for InfoPath 2007 and 2010, SQL Server 2005, 2008, and 2008 R2, SQL Server Management Studio Express 2005, Visual Studio 2005, 2008, and 2010. 1 1
MS11-067: Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230): Microsoft has released a set of patches for Microsoft Visual Studio 2005 SP1 and the Microsoft Report Viewer 2005 SP1 Redistributable Package. 1 1
Security Updates for Windows Malicious Software Removal Tool (January 2023): Microsoft has released version 5.109 to address this issue. 1 1
Node.js Module node-tar < 6.2.1 DoS: Upgrade to node-tar version 6.2.1 or later. 1 1
Install KB5002622 1 1
Install KB3115419 1 1
Install KB3115279 1 1
Security Updates for Microsoft OneNote Products (April 2025): Microsoft has released KB5002622 to address this issue. 1 1
KB4483229: Windows 10 Version 1607 and Windows Server 2016 December 2018 OOB Security Update: Apply Cumulative Update KB4483229. 1 1
Security Updates for SQL Server Management Studio (April 2025): Microsoft has released SSMS version 20.2.1 to address this issue. 1 1
Veeam Agent for Microsoft Windows 6.x < 6.3.2.1205 Privilege Escalation (CVE-2025-24287): Upgrade to Veeam Agent for Microsoft Windows version 6.3.2.1205 or later. 0 1
Microsoft Azure Data Studio < 1.48.0 Elevation of Privilege Vulnerability (CVE-2024-26203): Upgrade to Microsoft Azure Data Studio version 1.48.0 or later. 0 5
© 2026 Tenable™, Inc. All rights reserved.