Microsoft · Windows Vista · CVE-2016-3225
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows Vista SP2
Microsoft Windows Server 2008 SP2 and R2 SP1
Microsoft Windows 7 SP1
Microsoft Windows 8.1
Microsoft Windows Server 2012 Gold and R2
Microsoft Windows RT 8.1
Microsoft Windows 10 Gold and 1511
**Description**
The issue is related to the SMB server component in Microsoft Windows, which has inadequate access restrictions. This allows a local attacker to gain elevated privileges by using a specially crafted application that forwards an authentication request to an unintended service. The vulnerability can be exploited to affect the system.
**Recommendations**
For Microsoft Windows Vista SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2008 SP2 and R2 SP1, update to a newer version to mitigate the risk.
For Microsoft Windows 7 SP1, update to a newer version to mitigate the risk.
For Microsoft Windows 8.1, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk.
For Microsoft Windows RT 8.1, update to a newer version to mitigate the risk.
For Microsoft Windows 10 Gold and 1511, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the SMB server component until a patch is available.