CVE-2016-0197
published 2016-05-11CVE-2016-0197: dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.50%
71.3th percentile
dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_vista_service_pack_2 | — | — |
| msrc | windows_vista_x64_edition_service_pack_2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mx6-9mw9-88cc: dxgkrnl
ghsa_unreviewed·2022-05-14
CVE-2016-0197 [HIGH] GHSA-2mx6-9mw9-88cc: dxgkrnl
dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."
Microsoft
Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability
vendor_msrc·2016-05-10·CVSS 7.8
CVE-2016-0197 [HIGH] Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability
Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory. In a local attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to take control over the affected system.
An attacker who successfully exploited this vulnerability could run processes in an elevated context.
The update addresses the vulnerability by correcting the way the Microsoft DirectX graphics kernel subsystem (dxgkrnl.sys) handles certain calls and escapes, to preclude improper memory mapping and to prevent unintended elevation from user mode.
Windows Kernel-Mode Drivers: Windows Kernel-Mode Drivers
Impact:
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
## Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink .
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated Critical Vulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink.
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated CriticalVulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in this month's release.
MS16-051and MS16-
Bugzilla
CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
bugzilla·2016-03-14·CVSS 8.8
CVE-2016-1969 [HIGH] CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
Security researcher James Clawson used the Address Sanitizer tool to discover an out-of-bounds write in the Graphite 2 library when loading a crafted Graphite font file. This results in a potentially exploitable crash.
External references:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-38/
Discussion:
This security flaw was addressed in the following Firefox update:
https://rhn.redhat.com/errata/RHSA-2016-0197.html
Bugzilla
CVE-2016-1521 graphite2: Out-of-bound read vulnerability triggered by crafted fonts
bugzilla·2016-02-09·CVSS 8.8
CVE-2016-1521 [HIGH] CVE-2016-1521 graphite2: Out-of-bound read vulnerability triggered by crafted fonts
CVE-2016-1521 graphite2: Out-of-bound read vulnerability triggered by crafted fonts
An exploitable out-of-bound read vulnerability was found in the opcode handling functionality of Libgraphite. A specially crafted font can cause an out-of-bounds read resulting in arbitrary code execution. An attacker can provide a malicious font to trigger this vulnerability.
External References:
http://www.talosintel.com/reports/TALOS-2016-0058/
Discussion:
Created graphite2 tracking bugs for this issue:
Affects: fedora-all [bug 1305806]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:0197 https://rhn.redhat.com/errata/RHSA-2016-0197.html
---
This issue has been addressed in the followin
Bugzilla
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
bugzilla·2016-02-09·CVSS 6.5
CVE-2016-1523 [MEDIUM] CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
An exploitable heap-based buffer overflow was found in the context item handling functionality of Libgraphite. A specially crafted font can cause a buffer overflow resulting in potential code execution. An attacker can provide a malicious font to trigger this vulnerability.
External Reference:
http://www.talosintel.com/reports/TALOS-2016-0059/
Discussion:
Created graphite2 tracking bugs for this issue:
Affects: fedora-all [bug 1305814]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:0197 https://rhn.redhat.com/errata/RHSA-2016-0197.html
---
This issue has been addressed in the follo
http://www.securityfocus.com/bid/90102http://www.securitytracker.com/id/1035841https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062http://www.securityfocus.com/bid/90102http://www.securitytracker.com/id/1035841https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062
2016-05-11
Published