Описание
Windows PDF Information Disclosure Vulnerability
An information disclosure vulnerability exists in Microsoft Windows when a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could read memory in the context of the current user.
To exploit the vulnerability, an attacker would have to trick the user into opening the PDF file.
The update addresses the vulnerability by modifying how Windows parses PDF files.
FAQ
For my particular system and Microsoft Edge configuration, which update addresses the vulnerability discussed in CVE-2016-3201, CVE-2016-3203, or CVE-2016-3215? The vulnerabilities addressed by the updates for CVE-2016-3201, CVE-2016-3203, and CVE-2016-3215 released in MS16-068 are for systems running Microsoft Edge. These CVEs are also addressed for operating system components in MS16-080. MS16-068 and MS16-080 are addressed by this month’s cumulative Windows 10 update.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Windows Server 2012 | ||
Windows 8.1 for 32-bit systems | ||
Windows 8.1 for x64-based systems | ||
Windows Server 2012 R2 | ||
Windows 10 Version 1511 for x64-based Systems | ||
Windows 10 Version 1511 for 32-bit Systems | ||
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for 32-bit Systems | ||
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
Связанные уязвимости
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
Уязвимость операционной системы Windows и браузера Microsoft Edge, позволяющая нарушителю получить конфиденциальную информацию
EPSS