CVE-2016-0179: Critical severity windows 10 vulnerability
Published May 11, 2016
·Updated
Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Shell Remote Code Execution Vulnerability."
Affected Software
5 affected components
Microsoft Windows 10
Microsoft Windows 10=1511
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2012=r2
Event History
May 11, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
Which systems are exposed to this vulnerability?
Systems running Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, or Windows 10 Gold or 1511 are identified as affected. Exposure depends on a user visiting an attacker-controlled crafted website.
2
What does an attacker need to exploit this issue?
The attacker does not need prior privileges, but exploitation requires user interaction: the target must visit a crafted website. Successful exploitation can result in arbitrary code execution with high impact to confidentiality, integrity, and availability.