PT-2016-1993 · Microsoft · Windows+2

Published

2016-05-10

·

Updated

2018-10-12

·

CVE-2016-0188

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer 11 Windows (affected versions not specified)
Description The issue is related to a security feature bypass in the User Mode Code Integrity (UMCI) implementation of Device Guard in Microsoft Internet Explorer 11. This allows remote attackers to bypass a code-signing protection mechanism. Additionally, there is a component in the Windows operating system, specifically the Volume Manager Driver, that is vulnerable due to a lack of user validation for the RemoteFX RDP USB function, potentially allowing a local attacker to read arbitrary files from the disk.
Recommendations For Microsoft Internet Explorer 11, update the User Mode Code Integrity (UMCI) component to properly validate code integrity. For Windows, consider restricting access to the RemoteFX RDP USB function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability in Windows.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01327
CVE-2016-0188

Affected Products

Internet Explorer
Internet Explorer 11
Windows