CVE-2016-3213High
WPAD Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists in Microsoft Windows when the Web Proxy Auto Discovery (WPAD) protocol falls back to a vulnerable proxy discovery process. An attacker who successfully exploited this vulnerability could bypass security and gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker could respond to NetBIOS name requests for WPAD. The update addresses the vulnerability by correcting how Windows handles proxy discovery.
🎯 Affected products30
- Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
- Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
- Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
- Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
- Internet Explorer 9 on Windows Vista Service Pack 2
- Internet Explorer 9 on Windows Vista x64 Edition Service Pack 2
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for Itanium-Based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
✅ Remediation
KB3161949 (Security Update) KB3163017 (Security Update) KB3163018 (Security Update) KB3160005 (Security Update)
🔗 References (13)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3213
- patchhttps://www.microsoft.com/download/details.aspx?familyid=9a65a6da-e3a7-4aae-82e6-ab42f017c5b8
- patchhttps://www.microsoft.com/download/details.aspx?familyid=3717677f-21ec-4bf8-b141-bb74f8e3ff55
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ae6a2a37-6821-47f3-9ddc-73eaf5f61b53
- patchhttps://www.microsoft.com/download/details.aspx?familyid=dafc588f-3db3-45f0-9d1c-849998ac2509
- patchhttps://www.microsoft.com/download/details.aspx?familyid=b1b56949-07f7-4fbb-a953-1bab27a6b0d3
- patchhttps://www.microsoft.com/download/details.aspx?familyid=a8b5ece3-06cd-4b2d-9cde-3868bc147619
- patchhttps://www.microsoft.com/download/details.aspx?familyid=917ed575-0170-48e0-89c0-41d7f5fc81e8
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e90dc190-83ba-4b87-8b2a-e29ef0d0c76f
- patchhttps://www.microsoft.com/download/details.aspx?familyid=6d7883f2-fea0-499f-8351-5061afb0fd62
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3163017
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3163018
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3160005