CVE-2016-3312
published 2016-08-09CVE-2016-3312: ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure…
PriorityP347critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
9.65%
95.0th percentile
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat7.0HIGH
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hf5-6fmh-h37q: ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain
ghsa_unreviewed·2022-05-14
CVE-2016-3312 [CRITICAL] CWE-200 GHSA-9hf5-6fmh-h37q: ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
OSV
linux-lts-xenial vulnerabilities
osv·2017-06-07·CVSS 5.0
linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3312-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the netfilter netlink implementation in the Linux
kernel did not properly validate batch messages. A local attacker with the
CAP_NET_ADMIN capability could use this to expose sensitive information or
cause a denial of service. (CVE-2016-7917)
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
It was discovered that th
Red Hat
mysql: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 fix (CPU Jan 2017)
vendor_redhat·2017-01-17·CVSS 7.0
CVE-2017-3312 [HIGH] mysql: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 fix (CPU Jan 2017)
mysql: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 fix (CPU Jan 2017)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS v3.0 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).
Multiple flaws were found in the way the mysqld_safe script handled creation of error log file. The
Microsoft
Universal Outlook Information Disclosure Vulnerability
vendor_msrc·2016-08-09·CVSS 4.3
CVE-2016-3312 [CRITICAL] Universal Outlook Information Disclosure Vulnerability
Universal Outlook Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Universal Outlook fails to establish a secure connection. An attacker could use this vulnerability to obtain the username and password of a user.
The update addresses the vulnerability by preventing Universal Outlook from disclosing usernames and passwords.
ActiveSyncProvider: ActiveSyncProvider
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3176492
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3176493
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - August 2016
blogs_talos·2016-08-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2016
This post was authored by Edmund Brumaghin and Jonah Samost
Today is Patch Tuesday for August 2016, and Microsoft has released several security bulletins and associated patches to resolve security issues across their products. This month’s patch release includes 9 bulletins addressing 28 vulnerabilities. Five of the bulletins Microsoft has released are rated Critical and address vulnerabilities in Internet Explorer, Edge, Windows Graphics Component, Microsoft Office, and the Windows PDF library. The remaining four bulletins are rated Important and address vulnerabilities in Windows Kernel-Mode Drivers, Secure Boot, Windows Authentication Methods, and ActiveSyncProvider.
## Bulletins Rated CriticalMicrosoft has listed bulletins MS16-095, MS16-096, MS16-097, MS16-099, MS16-102 as critical
Talos
Microsoft Patch Tuesday - August 2016
blogs_talos·2016-08-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2016
## Microsoft Patch Tuesday - August 2016
This post was authored by Edmund Brumaghin and Jonah Samost
Today is Patch Tuesday for August 2016, and Microsoft has released several security bulletins and associated patches to resolve security issues across their products. This month’s patch release includes 9 bulletins addressing 28 vulnerabilities. Five of the bulletins Microsoft has released are rated Critical and address vulnerabilities in Internet Explorer, Edge, Windows Graphics Component, Microsoft Office, and the Windows PDF library. The remaining four bulletins are rated Important and address vulnerabilities in Windows Kernel-Mode Drivers, Secure Boot, Windows Authentication Methods, and ActiveSyncProvider.
## Bulletins Rated Critical Microsoft has listed bulletins MS16-095, MS16-096
http://www.securityfocus.com/bid/92307http://www.securitytracker.com/id/1036577https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-103http://www.securityfocus.com/bid/92307http://www.securitytracker.com/id/1036577https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-103
2016-08-09
Published