PT-2016-1993 · Microsoft · Windows+2
Published
2016-05-10
·
Updated
2018-10-12
·
CVE-2016-0188
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer 11
Windows (affected versions not specified)
Description
The issue is related to a security feature bypass in the User Mode Code Integrity (UMCI) implementation of Device Guard in Microsoft Internet Explorer 11. This allows remote attackers to bypass a code-signing protection mechanism. Additionally, there is a component in the Windows operating system, specifically the Volume Manager Driver, that is vulnerable due to a lack of user validation for the RemoteFX RDP USB function, potentially allowing a local attacker to read arbitrary files from the disk.
Recommendations
For Microsoft Internet Explorer 11, update the User Mode Code Integrity (UMCI) component to properly validate code integrity.
For Windows, consider restricting access to the RemoteFX RDP USB function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability in Windows.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Internet Explorer 11
Windows