PT-2016-5434 · Microsoft · Windows Vista Sp2+2
Published
2016-09-13
·
Updated
2018-10-12
·
CVE-2016-3372
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista SP2
Microsoft Windows Server 2008 SP2
Description
The issue is related to the kernel API in Microsoft Windows not properly enforcing permissions. This allows local users to potentially spoof processes, spoof inter-process communication, or cause a denial of service by using a crafted application. An elevation-of-privilege vulnerability is present, which allows attackers to affect the system.
Recommendations
For Microsoft Windows Vista SP2 and Windows Server 2008 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008 R2
Windows Vista Sp2
Windows