CVE-2016-3302 Information

Description

Microsoft Windows 8.1 Windows Server 2012 R2 Windows RT 8.1 and Windows 10 Gold 1511 and 1607 when the lock screen is enabled do not properly restrict the loading of web content which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device aka \Windows Lock Screen Elevation of Privilege Vulnerability.\

CVSS Vector

CVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Reference

http://www.securityfocus.com/bid/92853 http://www.securitytracker.com/id/1036799 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-112

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

6.3

Share on: