First published: Tue Dec 20 2016(Updated: )
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information from process memory via a crafted application, aka "Windows Common Log File System Driver Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Windows 10 | ||
Windows 10 | =1511 | |
Windows 10 | =1607 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =gold | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7295 is rated as important, indicating a significant risk to systems.
To fix CVE-2016-7295, apply the security update provided by Microsoft for your affected Windows version.
CVE-2016-7295 affects multiple versions of Microsoft Windows, including Windows Vista, Windows 7, Windows 8.1, Windows 10, and various Windows Server versions.
CVE-2016-7295 is a local information disclosure vulnerability that can allow users to access sensitive information.
CVE-2016-7295 cannot be exploited remotely as it requires local access to the affected system.