Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
Multiple elevation of privilege vulnerabilities exist in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited the vulnerabilities could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit the vulnerabilities, an attacker would first have to log on to the target system. An attacker could then run a specially crafted application that could exploit the vulnerabilities and take control over an affected system. The update addresses the vulnerabilities by correcting how the Windows kernel-mode driver handles objects in memory.
Impact
- Elevation of Privilege
System / Technologies affected
- Windows Server 2008, 2008 R2, 2012, 2012 R2
- Windows Vista, 7, 8, 8.1, RT 8.1, 10
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/library/security/MS16-062
Vulnerability Identifier
Source
Related Link
Share with