CVE-2016-3302
published 2016-09-14CVE-2016-3302: Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict…
PriorityP430medium6.3CVSS 3.0
AVPACHPRNUIRSUCHIHAH
EPSS
2.36%
81.9th percentile
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device, aka "Windows Lock Screen Elevation of Privilege Vulnerability."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Lock Screen Elevation of Privilege Vulnerability
vendor_msrc·2016-09-13·CVSS 7.0
CVE-2016-3302 [MEDIUM] Windows Lock Screen Elevation of Privilege Vulnerability
Windows Lock Screen Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows improperly allows web content to load from the Windows lock screen. To exploit the vulnerability, an attacker with physical access to a user’s computer could either connect to a maliciously configured WiFi hotspot or insert a mobile broadband adaptor in the user’s computer.
An attacker who successfully exploited the vulnerability could potentially execute code on a user's locked computer. However, the attacker would have no way to either force a user to connect to the hotspot or control the default browser selection on the user’s computer.
The security update addresses the vulnerability by correcting the behavior of the Windows lock screen to prevent unintended
GHSA
GHSA-5qrj-x9xq-qc4p: Microsoft Windows 8
ghsa_unreviewed·2022-05-14
CVE-2016-3302 [MEDIUM] GHSA-5qrj-x9xq-qc4p: Microsoft Windows 8
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device, aka "Windows Lock Screen Elevation of Privilege Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92853http://www.securitytracker.com/id/1036799https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-112http://www.securityfocus.com/bid/92853http://www.securitytracker.com/id/1036799https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-112
2016-09-14
Published