PT-2016-2505 · Microsoft · Windows Server 2012+2
Publicado
2016-07-12
·
Atualizado
2018-10-12
·
CVE-2016-3250
CVSS v3.1
7.3
Alta
| Vetor | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2012
Windows 10 versions Gold and 1511
Description
The issue is related to the kernel-mode drivers in the operating system, which have inadequate access restrictions. This allows a local attacker to gain elevated privileges by using a specially crafted application. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For Microsoft Windows Server 2012, apply the necessary security updates to resolve the issue.
For Windows 10 versions Gold and 1511, apply the necessary security updates to resolve the issue.
As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.
Correção
LPE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows Server 2012
Windows
Windows 10