CVE-2016-3312 is an information disclosure vulnerability in the ActiveSyncProvider of Microsoft Windows 10 Gold and 1511, allowing attackers to discover user credentials due to Universal Outlook failing to establish a secure connection. This critical vulnerability, with a CVSS score of 9.1, has a low attack complexity and requires no user interaction, potentially leading to high confidentiality and integrity impacts. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score indicates significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x64:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.