PT-2016-2491 · Microsoft · Windows 10+4
Published
2016-07-13
·
Updated
2018-10-12
·
CVE-2016-3272
CVSS v3.1
2.8
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 8.1
Windows Server 2012 Gold and R2
Windows RT 8.1
Windows 10 Gold and 1511
Description
The issue is related to the mishandling of page-fault system calls by the kernel in the affected Windows versions. This allows local users to obtain sensitive information from an arbitrary process via a crafted application.
Recommendations
For Windows 8.1, consider applying the necessary patches or updates to resolve the issue.
For Windows Server 2012 Gold and R2, apply the relevant security updates to fix the problem.
For Windows RT 8.1, install the latest available patches to mitigate the risk.
For Windows 10 Gold and 1511, update to a newer version that includes the fix for this issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012