CVE-2016-0008

Published on: 01/12/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:13 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Certain versions of Windows 7 from Microsoft contain the following vulnerability:

The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows GDI32.dll ASLR Bypass Vulnerability."

  • CVE-2016-0008 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 4.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW NONE NONE

CVSS2 Score: 4.3 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Windows Kernel-Mode Driver Bugs Let Remote Users Execute Arbitrary Code and Bypass ASLR - SecurityTracker Third Party Advisory
VDB Entry
www.securitytracker.com
text/html
URL Logo SECTRACK 1034654
Microsoft Security Bulletin MS16-005 - Critical | Microsoft Docs Patch
Vendor Advisory
docs.microsoft.com
text/html
URL Logo MS MS16-005
Microsoft Wordpad Open Document Text OOBR Heap Overflow Vulnerability Not Applicable
www.verisign.com
text/html
URL Logo IDEFENSE 20160112 Microsoft Wordpad Open Document Text OOBR Heap Overflow Vulnerability

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 7-sp1AllAll
Operating
System
MicrosoftWindows 8-AllAllAll
Operating
System
MicrosoftWindows 8-AllAllAll
Operating
System
MicrosoftWindows 8.1-AllAllAll
Operating
System
MicrosoftWindows 8.1-AllAllAll
Operating
System
MicrosoftWindows Rt-AllAllAll
Operating
System
MicrosoftWindows Rt-AllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Rt 8.1-AllAllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2008-sp2AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2008r2sp1AllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Server 2012-AllAllAll
Operating
System
MicrosoftWindows Server 2012r2AllAllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
Operating
System
MicrosoftWindows Vista-sp2AllAll
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*:
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*:
  • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*:
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*: