PT-2016-1231 · Microsoft · Windows Server 2012 R2+3
Published
2016-02-09
·
Updated
2019-05-15
·
CVE-2016-0044
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 8.1
Windows Server versions 2012 R2
Windows RT versions 8.1
Description
The issue is related to insufficient input validation in the Sync Framework component, allowing remote attackers to cause a denial of service by sending specially crafted "change batch" data. This could lead to a SyncShareSvc service outage, preventing authenticated users from using the service. However, it does not allow an attacker to execute code or elevate their user rights.
Recommendations
For Microsoft Windows 8.1, consider restricting access to the SyncShareSvc service until a fix is available.
For Windows Server 2012 R2, avoid using the Sync Framework component with untrusted input data.
For Windows RT 8.1, as a temporary workaround, consider disabling the SyncShareSvc service to prevent potential exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2