CVE-2016-3354

Description

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka GDI Information Disclosure Vulnerability.

Risk Information

Base Score
3.4
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:R
EPSS Score
Exploitation Probability
5.73

Associated Vulnerability

VulnerabilityOS Platform
Windows Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3185611) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3185614) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3185614) - CumulativeWindows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Vista (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2008 R2 x64 Edition (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 7 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2012 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows Server 2012 R2 (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB3185911)Windows
Win32k Elevation of Privilege Vulnerability for Windows 8.1 (KB3185911)Windows
Windows Information Disclosure Vulnerability for Windows 10 (KB3185611)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21344Cumulative Update for Windows 10 for x64-based Systems (KB3185611)
PATCH-21346Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3185614)
PATCH-21345Cumulative Update for Windows 10 Version 1511 (KB3185614)
PATCH-21354Security Update for Windows Server 2008 x64 Edition (KB3185911)
PATCH-21350Security Update for Windows Server 2008 (KB3185911)
PATCH-21353Security Update for Windows Server 2008 x64 Edition (KB3185911)
PATCH-21349Security Update for Windows Vista (KB3185911)
PATCH-21356Security Update for Windows Server 2008 R2 x64 Edition (KB3185911)
PATCH-21355Security Update for Windows 7 for x64-based Systems (KB3185911)
PATCH-21351Security Update for Windows 7 (KB3185911)
PATCH-21358Security Update for Windows Server 2012 (KB3185911)
PATCH-21359Security Update for Windows Server 2012 R2 (KB3185911)
PATCH-21357Security Update for Windows 8.1 for x64-based Systems (KB3185911)
PATCH-21352Security Update for Windows 8.1 (KB3185911)
PATCH-21343Cumulative Update for Windows 10 (KB3185611)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234