PT-2016-1231 · Microsoft · Windows Server 2012 R2+3

Published

2016-02-09

·

Updated

2019-05-15

·

CVE-2016-0044

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 8.1 Windows Server versions 2012 R2 Windows RT versions 8.1
Description The issue is related to insufficient input validation in the Sync Framework component, allowing remote attackers to cause a denial of service by sending specially crafted "change batch" data. This could lead to a SyncShareSvc service outage, preventing authenticated users from using the service. However, it does not allow an attacker to execute code or elevate their user rights.
Recommendations For Microsoft Windows 8.1, consider restricting access to the SyncShareSvc service until a fix is available. For Windows Server 2012 R2, avoid using the Sync Framework component with untrusted input data. For Windows RT 8.1, as a temporary workaround, consider disabling the SyncShareSvc service to prevent potential exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00492
CVE-2016-0044

Affected Products

Windows
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2