SB2016071304 - Multiple vulnerabilities in Windows Kernel-Mode Drivers
Published: July 13, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Information disclosure in Win32k.sys driver (CVE-ID: CVE-2016-3251)
The vulnerability allows a local user to gain access to potentially sensitive data.
The vulnerability exists due to out-of-bounds read in Windows GDI component. A local attacker can gain access to potentially sensitive information on the system
Successful exploitation of this vulnerability will allow a local attacker to read potentially sensitive information on the system.
2) Memory corruption in Win32k.sys driver (CVE-ID: CVE-2016-3286)
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists doe to an error in Win32k.sys kernel-mode driver when handling certain objects in memory. A local user can elevate privileges on vulnerable system.
Successful exploitation of this vulnerability will allow a local attacker to executed arbitrary code with SYSTEM privileges.
3) Memory corruption in Win32k.sys driver (CVE-ID: CVE-2016-3254)
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists doe to an error in Win32k.sys kernel-mode driver when handling certain objects in memory. A local user can elevate privileges on vulnerable system.
Successful exploitation of this vulnerability will allow a local attacker to executed arbitrary code with SYSTEM privileges.
4) Memory corruption in Win32k.sys driver (CVE-ID: CVE-2016-3252)
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists doe to an error in Win32k.sys kernel-mode driver when handling certain objects in memory. A local user can elevate privileges on vulnerable system.
Successful exploitation of this vulnerability will allow a local attacker to executed arbitrary code with SYSTEM privileges.
5) Memory corruption in Win32k.sys driver (CVE-ID: CVE-2016-3250)
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists doe to an error in Win32k.sys kernel-mode driver when handling certain objects in memory. A local user can elevate privileges on vulnerable system.
Successful exploitation of this vulnerability will allow a local attacker to executed arbitrary code with SYSTEM privileges.
6) Memory corruption in Win32k.sys driver (CVE-ID: CVE-2016-3249)
The vulnerability allows a local user to obtain elevated privileges.
The vulnerability exists doe to an error in Win32k.sys kernel-mode driver when handling certain objects in memory. A local user can elevate privileges on vulnerable system.
Successful exploitation of this vulnerability will allow a local attacker to executed arbitrary code with SYSTEM privileges.
Remediation
Install update from vendor's website.