PT-2016-1053 · Microsoft · Windows
Publicado
2016-01-12
·
Atualizado
2019-05-15
·
CVE-2016-0008
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
The issue is related to the graphics device interface in Microsoft Windows, which lacks protection for certain data. This allows a remote attacker to bypass the Address Space Layout Randomization (ASLR) protection mechanism. The vulnerability exists in the way the Windows graphics device interface handles objects in memory, enabling an attacker to retrieve information that could lead to an ASLR bypass.
Recommendations
For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to the graphics device interface to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows