CVE-2016-0178

Description

The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles free operations, which allows remote attackers to execute arbitrary code via malformed RPC requests, aka RPC Network Data Representation Engine Elevation of Privilege Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
26.245

Associated Vulnerability

VulnerabilityOS Platform
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3156421) - CumulativeWindows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3156421) - CumulativeWindows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3156387) - CumulativeWindows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 x64 Edition (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Vista (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 7 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 R2 x64 Edition (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2012 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 8.1 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2012 R2 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 x64 Edition (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Vista (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 7 (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2008 R2 x64 Edition (KB3153171)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2012 (KB3153704)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB3153704)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows 8.1 (KB3153704)Windows
RPC Network Data Representation Engine Remote Code Execution Vulnerability for Windows Server 2012 R2 (KB3153704)Windows
Windows Graphics Component Information Disclosure Vulnerability for Windows 10 (KB3156387)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-20504Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3156421)
PATCH-20503Cumulative Update for Windows 10 Version 1511 (KB3156421)
PATCH-20502Cumulative Update for Windows 10 for x64-based Systems (KB3156387)
PATCH-20750Security Update for Windows Server 2008 x64 Edition (KB3153171)
PATCH-20746Security Update for Windows Server 2008 (KB3153171)
PATCH-20749Security Update for Windows Vista for x64-based Systems (KB3153171)
PATCH-20745Security Update for Windows Vista (KB3153171)
PATCH-20751Security Update for Windows 7 for x64-based Systems (KB3153171)
PATCH-20747Security Update for Windows 7 (KB3153171)
PATCH-20752Security Update for Windows Server 2008 R2 x64 Edition (KB3153171)
PATCH-20754Security Update for Windows Server 2012 (KB3153171)
PATCH-20753Security Update for Windows 8.1 for x64-based Systems (KB3153171)
PATCH-20748Security Update for Windows 8.1 (KB3153171)
PATCH-20755Security Update for Windows Server 2012 R2 (KB3153171)
PATCH-20608Security Update for Windows Server 2008 x64 Edition (KB3153171)
PATCH-20604Security Update for Windows Server 2008 (KB3153171)
PATCH-20607Security Update for Windows Vista for x64-based Systems (KB3153171)
PATCH-20603Security Update for Windows Vista (KB3153171)
PATCH-20609Security Update for Windows 7 for x64-based Systems (KB3153171)
PATCH-20605Security Update for Windows 7 (KB3153171)
PATCH-20610Security Update for Windows Server 2008 R2 x64 Edition (KB3153171)
PATCH-20612Security Update for Windows Server 2012 (KB3153704)
PATCH-20611Security Update for Windows 8.1 for x64-based Systems (KB3153704)
PATCH-20606Security Update for Windows 8.1 (KB3153704)
PATCH-20613Security Update for Windows Server 2012 R2 (KB3153704)
PATCH-20501Cumulative Update for Windows 10 (KB3156387)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234