PT-2016-2505 · Microsoft · Windows Server 2012+2
Published
2016-07-12
·
Updated
2018-10-12
·
CVE-2016-3250
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2012
Windows 10 versions Gold and 1511
Description
The issue is related to the kernel-mode drivers in the operating system, which have inadequate access restrictions. This allows a local attacker to gain elevated privileges by using a specially crafted application. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For Microsoft Windows Server 2012, apply the necessary security updates to resolve the issue.
For Windows 10 versions Gold and 1511, apply the necessary security updates to resolve the issue.
As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2012
Windows
Windows 10