CVE-2016-0181High

Hypervisor Code Integrity Security Feature Bypass

Published
May 10, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists when Windows incorrectly allows certain kernel-mode pages to be marked as Read, Write, Execute (RWX) even with Hypervisor Code Integrity (HVCI) enabled. To exploit this vulnerability, an attacker could run a specially crafted application to bypass code integrity protections in Windows. The security update addresses the vulnerability by correcting security feature behavior to preclude the incorrect marking of RWX pages under HVCI.

🎯 Affected products4

  • Windows 10 Version 1511 for 32-bit Systems
  • Windows 10 Version 1511 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems

✅ Remediation

KB3156387 (Security Update) KB3156421 (Security Update)

🔗 References (3)