CVE-2016-3312
9.1
CRITICAL · CVSS 3.0 · EPSS 9.7% (pctl 95)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 9.65% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-08-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | windows 10 |
References
- http://www.securityfocus.com/bid/92307
- http://www.securitytracker.com/id/1036577
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-103
- http://www.securityfocus.com/bid/92307
- http://www.securitytracker.com/id/1036577
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-103
→ the Explorer · watch your stack · NVD