MS16-077: Security Update for WPAD (3165191)

Critical Nessus Plugin ID 91605

Synopsis

The remote host is affected by multiple elevation of privilege vulnerabilities.

Description

The remote Windows host is missing a security update. It is, therefore, affected by multiple elevation of privilege vulnerabilities :

- An elevation of privilege vulnerability exists in the Web Proxy Auto Discovery (WPAD) protocol due to improper handling of the proxy discovery process. A remote attacker can exploit this, by responding to NetBIOS name requests for WPAD, to bypass security restrictions and gain elevated privileges. (CVE-2016-3213)

- An elevation of privilege vulnerability exists in the Web Proxy Auto Discovery (WPAD) protocol due to improper handling of certain proxy discovery scenarios. A remote attacker can exploit this to elevate privileges, resulting in the ability to disclose or control network traffic. (CVE-2016-3236)

- An elevation of privilege vulnerability exists in NetBIOS due to improper handling of responses. A remote attacker can exploit this, via specially crafted NetBIOS responses, to appear as a trusted network device, resulting in the ability to render untrusted content in a browser outside of Enhanced Protected Mode (EPM) or an application container. (CVE-2016-3299)

Solution

Microsoft has released a set of patches for Windows Vista, 2008, 7, 2008 R2, 8, 2012, 8.1, RT 8.1, 2012 R2, and 10.

Note that cumulative update 3160005 in MS16-063 must also be installed in order to fully resolve CVE-2016-3213.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2016/ms16-077

Plugin Details

Severity: Critical

ID: 91605

File Name: smb_nt_ms16-077.nasl

Version: 1.10

Type: local

Agent: windows

Published: 2016/06/14

Updated: 2018/11/15

Dependencies: 13855, 57033

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/06/14

Vulnerability Publication Date: 2016/06/14

Exploitable With

Core Impact

Reference Information

CVE: CVE-2016-3213, CVE-2016-3236, CVE-2016-3299

BID: 91111, 91114, 92387

MSFT: MS16-077

MSKB: 3163017, 3161949, 3163018

IAVA: 2016-A-0157