PT-2016-2491 · Microsoft · Windows 10+4

Published

2016-07-13

·

Updated

2018-10-12

·

CVE-2016-3272

CVSS v3.1

2.8

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows 8.1 Windows Server 2012 Gold and R2 Windows RT 8.1 Windows 10 Gold and 1511
Description The issue is related to the mishandling of page-fault system calls by the kernel in the affected Windows versions. This allows local users to obtain sensitive information from an arbitrary process via a crafted application.
Recommendations For Windows 8.1, consider applying the necessary patches or updates to resolve the issue. For Windows Server 2012 Gold and R2, apply the relevant security updates to fix the problem. For Windows RT 8.1, install the latest available patches to mitigate the risk. For Windows 10 Gold and 1511, update to a newer version that includes the fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01882
CVE-2016-3272

Affected Products

Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012