PT-2016-1993 · Microsoft · Windows+2

Publicado

2016-05-10

·

Atualizado

2018-10-12

·

CVE-2016-0188

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer 11 Windows (affected versions not specified)
Description The issue is related to a security feature bypass in the User Mode Code Integrity (UMCI) implementation of Device Guard in Microsoft Internet Explorer 11. This allows remote attackers to bypass a code-signing protection mechanism. Additionally, there is a component in the Windows operating system, specifically the Volume Manager Driver, that is vulnerable due to a lack of user validation for the RemoteFX RDP USB function, potentially allowing a local attacker to read arbitrary files from the disk.
Recommendations For Microsoft Internet Explorer 11, update the User Mode Code Integrity (UMCI) component to properly validate code integrity. For Windows, consider restricting access to the RemoteFX RDP USB function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability in Windows.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01327
CVE-2016-0188

Produtos afetados

Internet Explorer
Internet Explorer 11
Windows