PT-2016-2977 · Microsoft · Windows Vista+7

Published

2016-10-11

·

Updated

2018-10-12

·

CVE-2016-3270

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to Windows 10 1703 Windows Vista SP2 Windows Server 2008 SP2 and R2 SP1 Windows 7 SP1 Windows 8.1 Windows Server 2012 Gold and R2 Windows RT 8.1 Windows 10 Gold, 1511, and 1607
Description The issue is related to insufficient access restrictions in the Graphics component of the Windows kernel, allowing a remote attacker to potentially elevate privileges using a specially crafted application. This can enable local users to gain privileges, affecting the system.
Recommendations For Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, update to a newer version of Windows to resolve the issue. For other affected versions, update to Windows 10 1703 or later to mitigate the risk. As a temporary workaround, consider restricting access to the Graphics component until a patch is available.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02409
CVE-2016-3270

Affected Products

Windows
Windows 10
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2012
Windows Vista