CVE-2016-3287
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot…
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."
- CVSS 3.0
- 4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- microsoft/windows 10 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2012
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/91604
- http://www.securitytracker.com/id/1036290
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-094
- http://www.securityfocus.com/bid/91604
- http://www.securitytracker.com/id/1036290
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-094
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.