PT-2016-5434 · Microsoft · Windows Vista Sp2+2

Published

2016-09-13

·

Updated

2018-10-12

·

CVE-2016-3372

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2
Description The issue is related to the kernel API in Microsoft Windows not properly enforcing permissions. This allows local users to potentially spoof processes, spoof inter-process communication, or cause a denial of service by using a crafted application. An elevation-of-privilege vulnerability is present, which allows attackers to affect the system.
Recommendations For Microsoft Windows Vista SP2 and Windows Server 2008 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3372

Affected Products

Windows Server 2008 R2
Windows Vista Sp2
Windows