PT-2016-5434 · Microsoft · Windows Vista Sp2+2
Publicado
2016-09-13
·
Atualizado
2018-10-12
·
CVE-2016-3372
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista SP2
Microsoft Windows Server 2008 SP2
Description
The issue is related to the kernel API in Microsoft Windows not properly enforcing permissions. This allows local users to potentially spoof processes, spoof inter-process communication, or cause a denial of service by using a crafted application. An elevation-of-privilege vulnerability is present, which allows attackers to affect the system.
Recommendations
For Microsoft Windows Vista SP2 and Windows Server 2008 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows Server 2008 R2
Windows Vista Sp2
Windows