CVE-2016-3320
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafted boot…
Does this matter?
Lower severity and a low EPSS score (5.01%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafted boot manager, aka "Secure Boot Security Feature Bypass."
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 5.01% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- microsoft/windows 10 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2012 · fedoraproject/fedora
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/92304Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036573Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-100Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MVB6Y2TVKSOBTIIBRUAJUIH3LQHMHCAG/
- http://www.securityfocus.com/bid/92304Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036573Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-100Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MVB6Y2TVKSOBTIIBRUAJUIH3LQHMHCAG/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.