CVE-2016-3300HighCVSS 6.8
NetLogon Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists when Windows Netlogon improperly establishes a secure communications channel to a domain controller. An attacker who successfully exploited the vulnerability could run a specially crafted application on a domain-joined system. To exploit the vulnerability, an attacker would require access to a domain-joined machine that points to a domain controller running either Windows Server 2012 or Windows Server 2012 R2. The update addresses the vulnerability by modifying how Netlogon handles the establishment of secure channels.
🎯 Affected products7
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
✅ Remediation
KB3177108 (Security Update)
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3300
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=c36cfcce-9a48-46d1-8191-184e2d12c464
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=78bbd98a-a91a-4cc6-b6c1-b34a6d195a52
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=14a50307-f863-4cc8-a009-480f63861e3a