CERT-In Vulnerability Note
CIVN-2016-0318
Windows Kernel Memory Information Disclosure Vulnerability
Original Issue Date:December 14, 2016
Severity Rating: MEDIUM
Software Affected
- Microsoft Windows 10 for 32-bit Systems
- Microsoft Windows 10 for x64-based Systems
- Microsoft Windows 10 version 1511 for 32-bit Systems
- Microsoft Windows 10 version 1511 for x64-based Systems
- Microsoft Windows 10 Version 1607 for 32-bit Systems
- Microsoft Windows 10 Version 1607 for 64-bit Systems
- Microsoft Windows Server 2016 for 64-bit Systems
Overview
A vulnerability has been reported in Microsoft Windows which could allow an authenticated, local attacker to access sensitive information.
Description
This vulnerability exists in Microsoft windows kernel due to improper handling of certain page fault system calls. A remote attacker with physical access to a targeted system could exploit this vulnerability by either connecting or by convincing a locally authenticated user to execute especially crafted application or malicious program whose .
successful exploitation could disclose sensitive information from one process to another.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS16-152
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms16-152
https://support.microsoft.com/en-us/kb/3199709
References
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=49975
Symantec
https://www.symantec.com/security_response/vulnerability.jsp?bid=94736
CVE Name
CVE-2016-7258
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|