SB2016051008 - Internet Explorer UMCI Bypass 



SB2016051008 - Internet Explorer UMCI Bypass

Published: May 10, 2016

Security Bulletin ID SB2016051008
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security bypass (CVE-ID: CVE-2016-0188)

The vulnerabiity allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to improper validation of code integrity by the User Mode Code Integrity (UMCI) component of Device Guard. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, bypass code-signing protection mechanism and execute a malicious code.

Successful exploitation of this vulnerability may result in arbitrary code execution on the vulnerable system.

Remediation

Install update from vendor's website.