CVE-2016-7219
The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain…
Does this matter?
Lower severity and a low EPSS score (3.43%). Track it; it rarely justifies an emergency change on its own.
Description
The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Crypto Driver Information Disclosure Vulnerability."
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.43% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/windows 10 · microsoft/windows 7 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows server 2016 · microsoft/windows vista
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/94764Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037450Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-149
- http://www.securityfocus.com/bid/94764Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037450Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-149
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.