Lucene search

K
mskbMicrosoftKB3178539
HistorySep 13, 2016 - 7:00 a.m.

MS16-112: Description of the security update for Windows lock screen: September 13, 2016

2016-09-1307:00:00
Microsoft
support.microsoft.com
54

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

CVSS3

6.3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0.006

Percentile

79.2%

MS16-112: Description of the security update for Windows lock screen: September 13, 2016

Summary

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if Windows improperly allows web content to load from the Windows lock screen.

To learn more about the vulnerability, see Microsoft Security Bulletin MS16-112.

More Information

Important

  • All future security and non-security updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see
Get security updates automatically.

Note For Windows RT 8.1, this update is available through Windows Update only.

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

__

Method 3: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS16-112 that corresponds to the version of Windows that you are running.

More Information

__

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

File Information

__

File hash information

File name SHA1 hash SHA256 hash
Windows8.1-KB3178539-x64.msu 60A85967F423AC37429757D8FBF7212540DEA922 EAB98A9AB742833DD689E07F2C902D81B6F6B09ECF11D21A38CA3B7CA4F2B99A
Windows8.1-KB3178539-x86.msu BCF957A9F18D52C7D6920CCCAF1967CD91DEF40B 86E1A36A57CD2FA87B46595A15B29ECEAE31FDBF87DFF71D17DD0B4E542F2A46

__

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.Windows 8.1 and Windows Server 2012 R2 file informationNotes: The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.For all supported x64-based versionsFile name File version File size Date Time Platform
Pnidui.dll 6.3.9600.18437 627,200 11-Aug-2016 16:17 x64
Pnidui.ptxml Not applicable 1,495 22-Aug-2013 06:47 Not applicable
Wwanconn.dll 8.1.9600.18437 455,680 11-Aug-2016 16:16 x64
Wwanmm.dll 8.1.9600.18437 1,156,608 11-Aug-2016 16:26 x64
Wwanpref.dll 8.1.9600.17415 50,688 29-Oct-2014 02:17 x64
Wwanui.ptxml Not applicable 3,237 22-Aug-2013 06:58 Not applicable
For all supported x86-based versionsFile name File version File size Date Time Platform
Pnidui.dll 6.3.9600.18437 572,928 11-Aug-2016 15:48 x86
Pnidui.ptxml Not applicable 1,495 21-Aug-2013 23:42 Not applicable
Wwanconn.dll 8.1.9600.18437 373,760 11-Aug-2016 15:47 x86
Wwanmm.dll 8.1.9600.18437 1,119,232 11-Aug-2016 15:52 x86
Wwanpref.dll 8.1.9600.17415 41,984 29-Oct-2014 01:38 x86
Wwanui.ptxml Not applicable 3,237 21-Aug-2013 23:54 Not applicable

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

CVSS3

6.3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0.006

Percentile

79.2%