Vulnerability Name: CVE-2016-3342 (CCN-117289) Assigned: 2016-11-08 Published: 2016-11-08 Updated: 2018-10-12 Summary: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0026 , CVE-2016-3332 , CVE-2016-3333 , CVE-2016-3334 , CVE-2016-3335 , CVE-2016-3338 , CVE-2016-3340 , CVE-2016-3343 , and CVE-2016-7184 . CVSS v3 Severity: 7.8 High  (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H  )6.8 Medium  (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C  )Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  NoneUser Interaction (UI):  RequiredScope: Scope (S):  UnchangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
8.8 High  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H  )7.7 High  (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C  )Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  LowUser Interaction (UI):  NoneScope: Scope (S):  ChangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
CVSS v2 Severity: 9.3 High  (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C  )Exploitability Metrics: Access Vector (AV):  NetworkAccess Complexity (AC):  MediumAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
6.8 Medium  (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C  )Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAthentication (Au):  Single_InstanceImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
Vulnerability Type: CWE-119 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2016-3342  Source: CCN Type: Microsoft Security Bulletin MS16-134Security Update for Common Log File System Driver (3193706)  Source: CCN Type: Microsoft Security Bulletin MS16-153Security Update for Common Log File System Driver (3207328)  Source: BID Type: UNKNOWN94013  Source: CCN Type: BID-94013Microsoft Windows CVE-2016-3342 Local Privilege Escalation Vulnerability  Source: SECTRACK Type: UNKNOWN1037252  Source: MS Type: UNKNOWNMS16-134  Source: XF Type: UNKNOWNms-clfs-cve20163342-priv-esc(117289)  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1511:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:1607:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*  Configuration CCN 1 :cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_10:*:*:*:*:*:*:x64:*  AND  cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*    Denotes that component is vulnerable  Oval Definitions Definition ID Class Title Last Modified oval:org.cisecurity:def:1458 V Windows Common Log File System Driver Elevation of Privilege Vulnerability – CVE-2016-3342 (MS16-134) 2016-12-23 
  BACK   
  microsoft  windows 10 -    
microsoft  windows 10 1511    
microsoft  windows 10 1607    
microsoft  windows 7 * sp1    
microsoft  windows 8.1 *    
microsoft  windows rt 8.1 *    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2012 -    
microsoft  windows server 2012 r2    
microsoft  windows server 2016 -    
microsoft  windows vista * sp2    
microsoft  windows vista * sp2    
microsoft  windows vista * sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 
microsoft  windows 7 - sp1    
microsoft  windows 7 * sp1    
microsoft  windows server 2008 r2    
microsoft  windows server 2008 r2    
microsoft  windows server 2012 
microsoft  windows 8.1 - -    
microsoft  windows 8.1 * 
microsoft  windows server 2012 r2    
microsoft  windows rt 8.1 * 
microsoft  windows 10 - 
microsoft  windows 10 * 
microsoft  windows server 2016