Vulnerability Name: | CVE-2016-3216 (CCN-113662) | ||||||||||||
Assigned: | 2016-06-14 | ||||||||||||
Published: | 2016-06-14 | ||||||||||||
Updated: | 2018-10-12 | ||||||||||||
Summary: | GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows Graphics Component Information Disclosure Vulnerability." | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C)
3.0 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-3216 Source: CCN Type: Microsoft Security Bulletin MS16-074 Security Update for Microsoft Graphics Component (3164036) Source: CCN Type: Microsoft Security Bulletin MS16-132 Security Update for Microsoft Graphics Component (3199120) Source: CCN Type: Microsoft Security Bulletin MS16-146 Security Update for Microsoft Graphics Component (3204066) Source: CCN Type: Microsoft Security Bulletin MS17-013 Security Update for Microsoft Graphics Component (4013075) Source: SECTRACK Type: UNKNOWN 1036101 Source: MS Type: UNKNOWN MS16-074 Source: XF Type: UNKNOWN ms-gdi-cve20163216-info-disc(113662) Source: CCN Type: Packet Storm Security [06-20-2016] Windows gdi32.dll Out-Of-Bounds Read / Memory Disclosure Source: CCN Type: Packet Storm Security [07-27-2016] Microsoft GDI+ Untrusted Data Filter Bypass Source: EXPLOIT-DB Type: UNKNOWN 39990 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |