VulnerabilityModified
CVE-2016-0181
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity…
MEDIUM 5.5EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass."
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- microsoft/windows 10
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/90048
- http://www.securitytracker.com/id/1035843
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-066
- http://www.securityfocus.com/bid/90048
- http://www.securitytracker.com/id/1035843
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-066
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.