CVE ID | CVE-2016-3309 |
CVSS SCORE | 6.9, AV:L/AC:M/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Windows |
VULNERABILITY DETAILS |
The specific flaw exists within RGNOBJ objects. An integer overflow vulnerability occurs when an attacker combines rectangles with special coordinates. An attacker can leverage this vulnerability to escalate privileges and execute code under the context of SYSTEM.
|
ADDITIONAL DETAILS |
Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://technet.microsoft.com/library/security/MS16-098 |
DISCLOSURE TIMELINE |
|
CREDIT | bee13oy of CloverSec Labs |