CVE-2016-3344
published 2016-09-14CVE-2016-3344: The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows…
PriorityP414low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
3.81%
89.0th percentile
The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Secure Kernel Mode Information Disclosure Vulnerability
vendor_msrc·2016-09-13·CVSS 5.0
CVE-2016-3344 [LOW] Windows Secure Kernel Mode Information Disclosure Vulnerability
Windows Secure Kernel Mode Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Secure Kernel Mode improperly handles objects in memory. A locally authenticated attacker who successfully exploited this vulnerability could be able to read sensitive information on the target system.
To exploit this vulnerability, an attacker could run a specially crafted application on the target system. Note that the information disclosure vulnerability by itself would not be sufficient for an attacker to compromise a system. However, an attacker could combine this vulnerability with additional vulnerabilities to further exploit the system.
The update addresses the vulnerability by correcting how Windows Secure Kernel Mode handles objects in memory.
GHSA
GHSA-xvxv-v375-9q9p: The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka
ghsa_unreviewed·2022-05-14
CVE-2016-3344 [LOW] CWE-200 GHSA-xvxv-v375-9q9p: The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka
The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92855http://www.securitytracker.com/id/1036800https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-113http://www.securityfocus.com/bid/92855http://www.securitytracker.com/id/1036800https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-113
2016-09-14
Published