Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-080 | patch vendor advisory |
http://www.zerodayinitiative.com/advisories/ZDI-16-370 | vdb entry third party advisory |
http://www.securitytracker.com/id/1036099 | vdb entry third party advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-068 | patch vendor advisory |