CVE-2016-3258
published 2016-07-13CVE-2016-3258: Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to…
PriorityP419medium4.7CVSS 3.0
AVLACHPRLUINSUCNIHAN
EPSS
0.93%
56.5th percentile
Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:P/A:N
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows File System Security Feature Bypass Vulnerability
vendor_msrc·2016-07-12·CVSS 6.3
CVE-2016-3258 [MEDIUM] Windows File System Security Feature Bypass Vulnerability
Windows File System Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in the Windows kernel that could allow an attacker to exploit time of check time of use (TOCTOU) issues in file path-based checks from a low-integrity application. An attacker who successfully exploited this vulnerability could potentially modify files outside of a low-integrity level application.
To exploit the vulnerability, an attacker would need to take advantage of another vulnerability to compromise the sandbox process from a low-integrity application.
The security update addresses the vulnerability by adding a validation check on how a low-integrity application can use certain object manager features.
FAQ: I am running Windows Server 2012. Do I need to install the
GHSA
GHSA-4vw5-pwf9-rvmv: Race condition in the kernel in Microsoft Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-3258 [MEDIUM] GHSA-4vw5-pwf9-rvmv: Race condition in the kernel in Microsoft Windows 8
Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer and Edge security bulletins respectively
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
## Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer
http://www.securityfocus.com/bid/91606http://www.securitytracker.com/id/1036289https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-092http://www.securityfocus.com/bid/91606http://www.securitytracker.com/id/1036289https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-092
2016-07-13
Published