5.5
CVE-2016-3371
- EPSS 40.07%
- Veröffentlicht 14.09.2016 10:59:46
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows Server 2008 Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Vista Update sp2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 40.07% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.securitytracker.com/id/1036802
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-111
http://www.securityfocus.com/bid/92814
https://www.exploit-db.com/exploits/40429/