PT-2016-4087 · Microsoft · Windows 10+4
Publicado
2016-10-11
·
Atualizado
2018-10-12
·
CVE-2016-0075
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 8.1
Windows Server 2012 Gold and R2
Windows RT 8.1
Windows 10 versions Gold, 1511, and 1607
Description
The issue allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry. This is an elevation-of-privilege issue that affects the system.
Recommendations
For Windows 8.1, consider restricting access to sensitive registry information until a patch is available.
For Windows Server 2012 Gold and R2, restrict access to sensitive registry information to minimize the risk of exploitation.
For Windows RT 8.1, avoid using crafted applications that make API calls to access sensitive registry information.
For Windows 10 versions Gold, 1511, and 1607, restrict access to sensitive registry information to prevent privilege escalation.
Exploit
Correção
LPE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012