SB2016101124 - Windows Diagnostics Hub Elevation of Privilege



SB2016101124 - Windows Diagnostics Hub Elevation of Privilege

Published: October 11, 2016

Security Bulletin ID SB2016101124
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2016-7188)

The vulnerability allows a local user to obtain elevated privileges on the target system.
The weakness exists due to insufficient sanitization of user-supplied input by the Windows Diagnostics Hub Standard Collector Service. By executing a crafted application and causing unsecure library loading attackers can obtain root privileges on the affected system that allows them to execute arbitrary code with system privileges.
Succesful exploitation of the vulnerability may result in complete vulnerable system compromise.

Remediation

Install update from vendor's website.