Microsoft issues out-of-band security update for 64-bit versions of Windows 7 and Windows Server 2008 R2. KB4100480 addresses a security bug discovered by a security expert earlier this week. The bug was caused by a patch meant to fix the Meltdown vulnerability but accidentally opened the kernel memory wide open. The flaw is not remotely exploitable, and attackers need either physical access to a PC, or they need to infect the PC with malware beforehand to exploit the flaw. The accidental bit flip bug now has its own CVE identifier of CVE-2018-1038.
Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-issues-out-of-band-security-update-for-windows-7-and-windows-server-2008/