CVE-2016-0175
published 2016-05-11CVE-2016-0175: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2…
PriorityP415low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
3.82%
88.9th percentile
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to obtain sensitive information about kernel-object addresses, and consequently bypass the KASLR protection mechanism, via a crafted application, aka "Win32k Information Disclosure Vulnerability."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_vista_service_pack_2 | — | — |
| msrc | windows_vista_x64_edition_service_pack_2 | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc3.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx53-9f22-cghg: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-0175 [LOW] CWE-200 GHSA-fx53-9f22-cghg: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to obtain sensitive information about kernel-object addresses, and consequently bypass the KASLR protection mechanism, via a crafted application, aka "Win32k Information Disclosure Vulnerability."
Microsoft
Win32k Information Disclosure Vulnerability
vendor_msrc·2016-05-10·CVSS 3.3
CVE-2016-0175 [LOW] Win32k Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass. An attacker who successfully exploited this vulnerability could retrieve the memory address of a kernel object.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
The security update addresses the vulnerability by correcting how the Windows kernel handles memory addresses.
Windows Kernel-Mode Drivers: Windows Kernel-Mode Drivers
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Olde
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
blogs_talos·2016-09-06·CVSS 5.5
CVE-2016-4329 [MEDIUM] Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
## Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
Vulnerability discovered by Marcin 'Icewall' Noga of Cisco Talos.
## Overview
Talos is disclosing the presence of TALOS-2016-0175 / CVE-2016-4329, a local denial of service vulnerability within Kaspersky anti-virus. A system user is able to cause a denial of service attack against Kaspersky’s avpui.exe process by executing malicious code on a system. As a result, avpui.exe process protected by Kaspersky Self-Protection dies.
The vulnerability can only be exploited by a user who is already present on the system. Nevertheless, such a vulnerability potentially may be exploited by a malicious user who wished to cause anti-virus scanning to stop informing users about potential malicious activiti
Talos
Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
blogs_talos·2016-09-06·CVSS 5.5
CVE-2016-4329 [MEDIUM] Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
Vulnerability discovered by Marcin 'Icewall' Noga of Cisco Talos.
## Overview
Talos is disclosing the presence of TALOS-2016-0175 / CVE-2016-4329, a local denial of service vulnerability within Kaspersky anti-virus. A system user is able to cause a denial of service attack against Kaspersky’s avpui.exe process by executing malicious code on a system. As a result, avpui.exe process protected by Kaspersky Self-Protection dies.
The vulnerability can only be exploited by a user who is already present on the system. Nevertheless, such a vulnerability potentially may be exploited by a malicious user who wished to cause anti-virus scanning to stop informing users about potential malicious activities. This may comprise a step in a longer sequence of malicious activity. Administrators should ens
Talos
Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
blogs_talos·2016-08-26·CVSS 5.5
CVE-2016-4329 [MEDIUM] Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
Vulnerability discovered by Marcin ‘Icewall’ Noga of Cisco Talos.
### Overview
Talos is disclosing the presence of TALOS-2016-0175 / CVE-2016-4329, a local denial of service vulnerability within Kaspersky anti-virus. A system user is able to cause a denial of service attack against Kaspersky’s avpui.exe process by executing malicious code on a system. As a result, avpui.exe process protected by Kaspersky Self-Protection dies.
The vulnerability can only be exploited by a user who is already present on the system. Nevertheless, such a vulnerability potentially may be exploited by a malicious user who wished to cause anti-virus scanning to stop informing users about potential malicious activities. This may comprise a step in a longer sequence of malicious activity. Administrators should en
Talos
Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
blogs_talos·2016-08-26·CVSS 5.5
CVE-2016-4329 [MEDIUM] Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
## Vulnerability Spotlight: Kaspersky Unhandled Windows Messages Denial of Service Vulnerability
Vulnerability discovered by Marcin ‘Icewall’ Noga of Cisco Talos.
## Overview
Talos is disclosing the presence of TALOS-2016-0175 / CVE-2016-4329, a local denial of service vulnerability within Kaspersky anti-virus. A system user is able to cause a denial of service attack against Kaspersky’s avpui.exe process by executing malicious code on a system. As a result, avpui.exe process protected by Kaspersky Self-Protection dies.
The vulnerability can only be exploited by a user who is already present on the system. Nevertheless, such a vulnerability potentially may be exploited by a malicious user who wished to cause anti-virus scanning to stop informing users about potential malicious activiti
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
## Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink .
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated Critical Vulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink.
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated CriticalVulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in this month's release.
MS16-051and MS16-
Zscaler
Zscaler found Multiple Security Vulnerabilities | 05-11-2016
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler found Multiple Security Vulnerabilities | 05-11-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
arxiv_fulltext·2018-08-08
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Daehee Jang
KAIST
[email protected]
Hojoon Lee
KAIST
[email protected]
Brent Byunghoon Kang
KAIST
[email protected]
Michael Shell
Georgia Institute of Technology
[email protected]
Homer Simpson
Twentieth Century Fox
[email protected]
James Kirk
and Montgomery Scott
Starfleet Academy
[email protected]
\@IEEEpubidpullup9
Permission to freely reproduce all or part
of this paper for noncommercial purposes is granted provided that
copies bear this notice and the full citation on the first
page. Reproduction for commercial purposes is strictly prohibited
without the prior written consent of the Internet Society, the
first-named author (for reproduction of an entire paper only), and
the
Bugzilla
CVE-2016-8328 Oracle JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
bugzilla·2017-01-17·CVSS 3.7
CVE-2016-8328 [LOW] CVE-2016-8328 Oracle JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
CVE-2016-8328 Oracle JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
Oracle Java SE 8u121 fixes an unspecified vulnerability in the Java Mission Control component (CVE-2016-8328). Upstream has CVSS scored this issue as: 3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Via RHSA-2017:0175 https://rhn.redhat.com/errata/RHSA-2017-0175.html
http://www.securityfocus.com/bid/90027http://www.securitytracker.com/id/1035841http://www.zerodayinitiative.com/advisories/ZDI-16-281https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062http://www.securityfocus.com/bid/90027http://www.securitytracker.com/id/1035841http://www.zerodayinitiative.com/advisories/ZDI-16-281https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062
2016-05-11
Published