PT-2016-2569 · Microsoft · Windows Server 2012 R2+5

Published

2016-08-09

·

Updated

2019-05-15

·

CVE-2016-3320

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 8.1, 10 Gold, and 10 1511 Windows Server versions 2012 Gold and 2012 R2 Windows RT version 8.1
Description The issue is related to insufficient access control in the Windows operating system, allowing attackers to bypass the Secure Boot protection mechanism. This can be achieved by leveraging administrative or physical access to install a crafted boot manager. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For Windows 8.1, update to a newer version to mitigate the risk. For Windows Server 2012 Gold and R2, update to a newer version to mitigate the risk. For Windows RT 8.1, update to a newer version to mitigate the risk. For Windows 10 Gold and 1511, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting administrative and physical access to the system to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01961
CVE-2016-3320

Affected Products

Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2012 R2