SB2016101106 - Microsoft Video Control Remote Code Execution Vulnerability
Published: October 11, 2016
Security Bulletin ID
SB2016101106
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Arbitrary code execution (CVE-ID: CVE-2016-0142)
The vulnerability allows a remote unauthenticated user to execute arbitrary code on the target system.The weakness exists due to improper handling of objects within memory. By persuading the victim to open a malicious file a attackers can execute arbitrary code with privileges of the target user. If a valid user has elevated privileges, attacker can get complete control over the system.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Remediation
Install update from vendor's website.