PT-2016-2505 · Microsoft · Windows Server 2012+2

Published

2016-07-12

·

Updated

2018-10-12

·

CVE-2016-3250

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2012 Windows 10 versions Gold and 1511
Description The issue is related to the kernel-mode drivers in the operating system, which have inadequate access restrictions. This allows a local attacker to gain elevated privileges by using a specially crafted application. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For Microsoft Windows Server 2012, apply the necessary security updates to resolve the issue. For Windows 10 versions Gold and 1511, apply the necessary security updates to resolve the issue. As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01896
CVE-2016-3250

Affected Products

Windows Server 2012
Windows
Windows 10