PT-2016-2004 · Microsoft · Windows Vista+7

Published

2016-05-10

·

Updated

2018-10-12

·

CVE-2016-0175

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2 and R2 SP1 Microsoft Windows 7 SP1 Microsoft Windows 8.1 Microsoft Windows Server 2012 Gold and R2 Microsoft Windows RT 8.1 Microsoft Windows 10 Gold and 1511
Description The issue allows local users to obtain sensitive information about kernel-object addresses and bypass the KASLR protection mechanism via a crafted application. This is related to a lack of protection for internal data in kernel-mode drivers. The exploitation of this issue can enable a local attacker to gain confidential information and affect the system.
Recommendations For Microsoft Windows Vista SP2, consider applying a patch to fix the kernel-mode driver issue. For Microsoft Windows Server 2008 SP2 and R2 SP1, update the kernel-mode drivers to prevent information disclosure. For Microsoft Windows 7 SP1, apply a security update to address the kernel-object address exposure. For Microsoft Windows 8.1, restrict access to crafted applications that could exploit the kernel-mode driver vulnerability. For Microsoft Windows Server 2012 Gold and R2, implement additional security measures to protect against local attackers exploiting the KASLR bypass. For Microsoft Windows RT 8.1, disable the use of vulnerable font functions until a patch is available. For Microsoft Windows 10 Gold and 1511, update the operating system to a version that includes the fix for the kernel-mode driver information disclosure issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01338
CVE-2016-0175
ZDI-16-281

Affected Products

Windows
Windows 10
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2012
Windows Vista