PT-2016-1231 · Microsoft · Windows Server 2012 R2+3

Publicado

2016-02-09

·

Atualizado

2019-05-15

·

CVE-2016-0044

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 8.1 Windows Server versions 2012 R2 Windows RT versions 8.1
Description The issue is related to insufficient input validation in the Sync Framework component, allowing remote attackers to cause a denial of service by sending specially crafted "change batch" data. This could lead to a SyncShareSvc service outage, preventing authenticated users from using the service. However, it does not allow an attacker to execute code or elevate their user rights.
Recommendations For Microsoft Windows 8.1, consider restricting access to the SyncShareSvc service until a fix is available. For Windows Server 2012 R2, avoid using the Sync Framework component with untrusted input data. For Windows RT 8.1, as a temporary workaround, consider disabling the SyncShareSvc service to prevent potential exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00492
CVE-2016-0044

Produtos afetados

Windows
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2