CVE-2016-3228High
Windows NetLogon Memory Corruption Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution when Windows improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. To exploit the vulnerability, a domain-authenticated attacker could make a specially crafted NetLogon request to a domain controller. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights. This update corrects how Windows handles objects in memory to prevent corruption.
🎯 Affected products9
- Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for Itanium-Based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
✅ Remediation
KB3161561 (Security Update) KB3162343 (Security Update)
🔗 References (8)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3228
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3161561
- patchhttps://www.microsoft.com/download/details.aspx?familyid=db6cf8e6-34a6-4072-815b-1293e0ac0651
- patchhttps://www.microsoft.com/download/details.aspx?familyid=609f9342-af11-4178-9c03-bf5cdce2b12d
- patchhttps://www.microsoft.com/download/details.aspx?familyid=f8cadd40-123b-4a55-8b15-0f67cdec7a1b
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d6b2d554-eca6-460a-ba01-af6c207cdd38
- patchhttps://www.microsoft.com/download/details.aspx?familyid=9d865d51-86dc-4c1f-8b7a-fa699f8329de
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3162343