Lucene search

K
kasperskyKaspersky LabKLA10883
HistoryOct 11, 2016 - 12:00 a.m.

KLA10883 OSI vulnerability in Microsoft Products

2016-10-1100:00:00
Kaspersky Lab
threats.kaspersky.com
56

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.6%

An information disclosure vulnerability was found in Microsoft Products. Malicious users can exploit this vulnerability to obtain sensitive information.

Original advisories

CVE-2016-3209

Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Microsoft-.NET-Framework

Microsoft-Silverlight

Microsoft-Office-Live-Meeting-2007

Microsoft-Lync

Microsoft-Office

Microsoft-Lync-2010-Attendee

Microsoft-Word

Skype-for-Windows

Microsoft-Windows-Vista-4

Microsoft-Windows-Server-2012

Microsoft-Windows-8

Microsoft-Windows-7

Microsoft-Windows-Server-2008

Microsoft-Windows-10

CVE list

CVE-2016-3209 warning

KB list

3192441

3194798

3192440

3188735

3188732

3188730

3188731

3189040

3193713

3189051

3189052

3188726

3189039

3188743

3188741

3188740

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • Silverlight 5Windows Vista Service Pack 2Windows Server 2008 Service Pack 2Windows 7 Service Pack 1Windows Server 2008 R2 Service Pack 1Windows 8.1Windows Server 2012Windows Server 2012 R2Windows RT 8.1Windows 10Windows 10 1511, 1607.NET Framework versions 3.0 SP2, 3.5, 3.5.1,  4.5.2 and 4.6Office 2007 Service Pack 3Office 2010 Service Pack 2Word ViewerSkype for Business 2016Lync 2013 Service Pack 1Lync 2010Live Meeting 2007 Console

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.6%