CVE-2016-3287
published 2016-07-13CVE-2016-3287: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection…
PriorityP418medium4.4CVSS 3.0
AVLACLPRHUINSUCNIHAN
EPSS
1.49%
71.1th percentile
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Secure Boot Security Feature Bypass Vulnerability
vendor_msrc·2016-07-12·CVSS 6.2
CVE-2016-3287 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Windows Secure Boot improperly applies an affected policy. An attacker who successfully exploited this vulnerability could disable code integrity checks, allowing test-signed executables and drivers to be loaded on a target device. In addition, an attacker could bypass the Secure Boot Integrity Validation for BitLocker and the Device Encryption security features.
To exploit the vulnerability, an attacker must either gain administrative privileges or physical access to a target device to install an affected policy.
The security update addresses the vulnerability by blacklisting affected policies.
FAQ: I am running Windows Server 2012. Do I need to install the 3170377 and 3172
GHSA
GHSA-whq3-926m-h9qp: Microsoft Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-3287 [MEDIUM] GHSA-whq3-926m-h9qp: Microsoft Windows 8
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer and Edge security bulletins respectively
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
## Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer
http://www.securityfocus.com/bid/91604http://www.securitytracker.com/id/1036290https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-094http://www.securityfocus.com/bid/91604http://www.securitytracker.com/id/1036290https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-094
2016-07-13
Published