PT-2016-1053 · Microsoft · Windows
Published
2016-01-12
·
Updated
2019-05-15
·
CVE-2016-0008
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
The issue is related to the graphics device interface in Microsoft Windows, which lacks protection for certain data. This allows a remote attacker to bypass the Address Space Layout Randomization (ASLR) protection mechanism. The vulnerability exists in the way the Windows graphics device interface handles objects in memory, enabling an attacker to retrieve information that could lead to an ASLR bypass.
Recommendations
For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to the graphics device interface to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows