<< Back
CVE Number Vulnerability Product Severity Date
MS16-149 Security Update for Microsoft Windows (3205655) Windows Vista Important 14-12-2016

Technical Information

Brief overview of the risk:
An information disclosure vulnerability exists when a Windows Crypto driver running in kernel mode improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the userÆs system.

Detailed Information on the risk:

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. To exploit the vulnerability, a locally authenticated attacker could run arbitrary code with elevated system privileges.

Further information on this exploit is available at : MS16-149

Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows 8.1 for 32-bit Systems
Windows 8.1 for x64-based Systems
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems 
Windows 10 Version 1511 for 32-bit Systems 
Windows 10 Version 1511 for x64-based Systems 
Windows 10 Version 1607 for 32-bit Systems 
Windows 10 Version 1607 for x64-based Systems 
Windows Server 2016 for x64-based Systems

Affected Software

Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows 8.1 for 32-bit Systems
Windows 8.1 for x64-based Systems
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems 
Windows 10 Version 1511 for 32-bit Systems 
Windows 10 Version 1511 for x64-based Systems 
Windows 10 Version 1607 for 32-bit Systems 
Windows 10 Version 1607 for x64-based Systems 
Windows Server 2016 for x64-based Systems